← Voltar para CVEs
CVE-2017-3191
N/ADescricao
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page. A remote attacker that can access the remote management login page can manipulate the POST request in such a manner as to access some administrator-only pages such as tools_admin.asp without credentials.
Detalhes CVE
Pontuacao CVSS v3.1N/A
Publicado12/16/2017
Ultima modificacao4/20/2025
Fontenvd
Avistamentos honeypot0
Produtos afetados
d-link:dir-130_firmwared-link:dir-330_firmwaredlink:dir-130dlink:dir-330
Fraquezas (CWE)
CWE-294CWE-20
Referencias
https://exchange.xforce.ibmcloud.com/vulnerabilities/123293(cret@cert.org)
https://www.kb.cert.org/vuls/id/553503(cret@cert.org)
https://www.scmagazine.com/d-link-dir-130-and-dir-330-routers-vulnerable/article/644553/(cret@cert.org)
https://exchange.xforce.ibmcloud.com/vulnerabilities/123293(af854a3a-2127-422b-91ae-364da2661108)
https://www.kb.cert.org/vuls/id/553503(af854a3a-2127-422b-91ae-364da2661108)
https://www.scmagazine.com/d-link-dir-130-and-dir-330-routers-vulnerable/article/644553/(af854a3a-2127-422b-91ae-364da2661108)
https://www.wilderssecurity.com/threads/d-link-dir-130-and-dir-330-are-vulnerable-to-authentication-bypass-and-do-not-protect-credentials.392703/(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.