Insufficient Network Isolation in D-Link Router
CVE-2019-13264

8.8HIGH

Key Information:

Vendor
D-Link
Vendor
CVE Published:
27 August 2019

Summary

D-Link DIR-825AC G1 devices exhibit insufficient compartmentalization between host and guest networks. This vulnerability allows an attacker to transfer data from the host network to the guest network by manipulating IGMP group membership. Specifically, the sender can join and subsequently leave an IGMP group, causing the router to broadcast an IGMP Membership Query packet to both networks. This can lead to unauthorized data access and potential information leakage, as the data is transmitted within a Group IP field that is entirely under the sender's control. Proper isolation between host and guest networks is crucial for maintaining network security.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.