Incorrect Access Control Vulnerability in D-Link DSL-2750U and DSL-2730U Routers
CVE-2023-46033

6.8MEDIUM

Key Information:

Vendor
D-Link
Vendor
CVE Published:
19 October 2023

Summary

The D-Link DSL-2750U N300 ADSL2+ and DSL-2730U N150 ADSL2+ routers exhibit a serious flaw in their access control mechanisms. The UART/Serial interface on the circuit board provides access to sensitive log outputs and a root terminal, potentially allowing unauthorized users to exploit this vulnerability. Proper measures should be taken to secure these interfaces to prevent unauthorized access.

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.