Insecure Certificate and RSA Private Key Extraction in D-Link Devices
CVE-2019-14334

5.5MEDIUM

Key Information:

Vendor
D-Link
Vendor
CVE Published:
1 August 2019

Summary

A security vulnerability has been identified in certain D-Link wireless access points, where an insecure HTTP command allows for post-authentication extraction of sensitive data, including SSL certificates and RSA private keys. This issue affects the D-Link 6600-AP, DWL-3600AP, and DWL-8610AP models running firmware version Ax 4.2.0.14 as of March 21, 2019. Exploitation of this flaw could lead to unauthorized access to confidential information, emphasizing the necessity for users to update their devices and apply security patches promptly.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.