Authentication Bypass Vulnerability in D-Link Routers
CVE-2020-15633
8.8HIGH
Summary
This vulnerability affects D-Link DIR-867, DIR-878, and DIR-882 routers, allowing network-adjacent attackers to bypass authentication due to improper handling of HNAP requests. The flaw arises from incorrect string matching logic, enabling unauthorized access to protected pages. An attacker can exploit this vulnerability to escalate privileges and execute arbitrary code within the router's context.
Affected Version(s)
Multiple Routers 1.20B10_BETA
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
chung96vn of Vietnam Cyber Security Center