Command Line Interface Vulnerability in D-Link Devices
CVE-2019-14337

5.5MEDIUM

Key Information:

Vendor
D-Link
Vendor
CVE Published:
1 August 2019

Summary

An issue has been identified in D-Link 6600-AP and DWL-3600AP Ax devices, where an attacker can exploit a vulnerability to escape from a restricted command line interface. This is achieved through a crafted command sequence that allows unauthorized access to the system shell. Such misconfigurations can expose devices to various security risks, including unauthorized command execution, potentially compromising the integrity and confidentiality of the device and its network.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.