Multiple D-Link Products WPS-PIN Information Disclosure Vulnerability
BID:70903
Info
Multiple D-Link Products WPS-PIN Information Disclosure Vulnerability
| Bugtraq ID: | 70903 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 01 2014 12:00AM |
| Updated: | Nov 01 2014 12:00AM |
| Credit: | Craig of /dev/ttys0, and Hack-a-Day. |
| Vulnerable: |
D-Link DIR-857 0 D-Link DIR-855L 1.02b08 D-Link DIR-855 0 D-Link DIR-836L 0 D-Link DIR-835 1.04b04 D-Link DIR-835 0 D-Link DIR-827 0 D-Link DIR-826L 0 D-Link DIR-825 0 D-Link DIR-808L 0 D-Link DIR-657 0 D-Link DIR-655 0 D-Link DIR-651 0 D-Link DIR-636L 0 D-Link DIR-632 0 D-Link DIR-628 0 D-Link DIR-615 8.05b06 D-Link DIR-615 5.10 D-Link DIR-615 4.13B01 D-Link DIR-615 4.13 D-Link DIR-615 0 D-Link DIR-601 0 D-Link DIR-451 0 D-Link DHP-1320 0 D-Link DGL-4500 0 D-Link DAP-1555 0 D-Link DAP-1350 1.14 D-Link DAP-1350 1.10 D-Link DAP-1350 0 |
| Not Vulnerable: | |
Discussion
Multiple D-Link Products WPS-PIN Information Disclosure Vulnerability
Multiple D-Link products are prone to an information-disclosure vulnerability.
An attacker can exploit this issue to obtain sensitive information, and gain unauthorized access to the device. Successfully exploiting this issue may lead to further attacks.
Multiple D-Link products are prone to an information-disclosure vulnerability.
An attacker can exploit this issue to obtain sensitive information, and gain unauthorized access to the device. Successfully exploiting this issue may lead to further attacks.
Exploit / POC
Multiple D-Link Products WPS-PIN Information Disclosure Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Multiple D-Link Products WPS-PIN Information Disclosure Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].