Authentication Bypass Vulnerability in D-Link DIR-895 Router
CVE-2023-36091

9.8CRITICAL

Key Information:

Vendor

D-Link

Vendor
CVE Published:
31 July 2023

What is CVE-2023-36091?

An authentication bypass vulnerability exists in the D-Link DIR-895 router (FW102b07) that allows remote attackers to exploit the phpcgi_main function in the cgibin directory, potentially granting them escalated privileges. This vulnerability is particularly concerning as it affects products that are no longer supported by the manufacturer, leaving them vulnerable to attacks and exploitation.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.