Improper File Permissions in D-Link DIR-850L Routers by D-Link
CVE-2017-14428
7.8HIGH
Summary
Certain D-Link DIR-850L routers are susceptible to an improper file permissions vulnerability due to incorrectly set permissions on the /var/run/hostapd* files. These settings allow unauthorized users to potentially access sensitive information or execute malicious commands, which could compromise the integrity of the device and the network it serves. Ensuring that devices are updated and configured properly can help mitigate the risks associated with this vulnerability.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved