D-Link Good Line Router v2 HTTP GET Request devinfo information disclosure
CVE-2024-0717
Key Information:
Badges
Summary
A notable vulnerability exists within various D-Link networking devices, particularly impacting the HTTP GET Request Handler component. This flaw enables malicious actors to disclose sensitive information by manipulating arguments in the input area, specifically targeting the '/devinfo' file of the affected devices. The vulnerability can be exploited remotely, making it vital for users to take immediate action to secure their devices. As the exploit has been publicly disclosed, it is crucial for users to ensure their devices are updated and configured correctly to mitigate potential security risks.
Affected Version(s)
DAP-1360 20240112
DIR-1210 20240112
DIR-1260 20240112
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved