Exposed Administration Function in D-Link DIR-816L Devices
CVE-2020-15894
7.5HIGH
What is CVE-2020-15894?
The D-Link DIR-816L has a web application vulnerability due to an exposed administration function in the getcfg.php file. This vulnerability allows attackers to manipulate the _POST_SERVICES parameter to access sensitive information, including admin login credentials. Such exposure can lead to unauthorized access and potential compromise of the device. Users are advised to update their firmware to the latest version to mitigate this risk.