Authentication Bypass Vulnerability in D-Link Routers
CVE-2020-15633

8.8HIGH

Key Information:

Vendor
D-link
Vendor
CVE Published:
23 July 2020

Summary

This vulnerability affects D-Link DIR-867, DIR-878, and DIR-882 routers, allowing network-adjacent attackers to bypass authentication due to improper handling of HNAP requests. The flaw arises from incorrect string matching logic, enabling unauthorized access to protected pages. An attacker can exploit this vulnerability to escalate privileges and execute arbitrary code within the router's context.

Affected Version(s)

Multiple Routers 1.20B10_BETA

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

chung96vn of Vietnam Cyber Security Center
.