Firewall Bypass Vulnerability in D-Link R15 Devices
CVE-2023-41603

5.3MEDIUM

Key Information:

Vendor

D-Link

Vendor
CVE Published:
10 January 2024

What is CVE-2023-41603?

The D-Link R15 prior to version 1.08.02 is vulnerable due to the absence of firewall protections for IPv6 traffic. As a result, attackers gain the ability to exploit any services running on the device that are unintentionally exposed through IPv6 connections. This lack of adequate firewall restrictions can lead to significant security risks, allowing malicious actors to conduct unauthorized operations on the affected devices.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.