Authentication Bypass in D-Link DAP-1860 Devices
CVE-2019-19598
8.8HIGH
What is CVE-2019-19598?
The D-Link DAP-1860 devices prior to version 1.04b03 Beta are susceptible to an authentication bypass vulnerability that allows unauthorized access to administrator functions. This occurs due to improper validation of the HNAP_AUTH header timestamp value, which can be manipulated. If an attacker sends a request where the timestamp matches the stored value in the device's /var/hnap/timestamp file, the HNAP_AUTH check will erroneously validate the request, granting the attacker access to sensitive administrative functionalities. This flaw emphasizes the need for robust security measures in the management of network devices.