CVE-2019-7642
Summary
| CVE | CVE-2019-7642 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-25 22:29:00 UTC |
| Updated | 2021-04-23 15:45:00 UTC |
| Description | D-Link routers with the mydlink feature have some web interfaces without authentication requirements. An attacker can remotely obtain users' DNS query logs and login logs. Vulnerable targets include but are not limited to the latest firmware versions of DIR-817LW (A1-1.04), DIR-816L (B1-2.06), DIR-816 (B1-2.06?), DIR-850L (A1-1.09), and DIR-868L (A1-1.10). |
Risk And Classification
Problem Types: CWE-306
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Dlink | Dir-816 | b1 | All | All | All |
| Hardware | Dlink | Dir-816 | b1 | All | All | All |
| Hardware | Dlink | Dir-816l | b1 | All | All | All |
| Hardware | Dlink | Dir-816l | b1 | All | All | All |
| Operating System | Dlink | Dir-816l Firmware | 2.06 | All | All | All |
| Operating System | Dlink | Dir-816l Firmware | 2.06 | All | All | All |
| Operating System | Dlink | Dir-816 Firmware | 2.06 | All | All | All |
| Operating System | Dlink | Dir-816 Firmware | 2.06 | All | All | All |
| Hardware | Dlink | Dir-817lw | a1 | All | All | All |
| Hardware | Dlink | Dir-817lw | a1 | All | All | All |
| Operating System | Dlink | Dir-817lw Firmware | 1.04 | All | All | All |
| Operating System | Dlink | Dir-817lw Firmware | 1.04 | All | All | All |
| Hardware | Dlink | Dir-850l | a1 | All | All | All |
| Hardware | Dlink | Dir-850l | a1 | All | All | All |
| Operating System | Dlink | Dir-850l Firmware | 1.09 | All | All | All |
| Operating System | Dlink | Dir-850l Firmware | 1.09 | All | All | All |
| Hardware | Dlink | Dir-868l | a1 | All | All | All |
| Hardware | Dlink | Dir-868l | a1 | All | All | All |
| Operating System | Dlink | Dir-868l Firmware | 1.10 | All | All | All |
| Operating System | Dlink | Dir-868l Firmware | 1.10 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2019-7642/README.md at master · xw77cve/CVE-2019-7642 · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.