7.5
CVSSv3

CVE-2017-14422

Published: 13/09/2017 Updated: 08/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices use the same hardcoded /etc/stunnel.key private key across different customers' installations, which allows remote malicious users to defeat the HTTPS cryptographic protection mechanisms by leveraging knowledge of this key from another installation.

Vulnerable Product Search on Vulmon Subscribe to Product

dlink dir-850l_firmware

dlink dir-850l_firmware fw114wwb07_h2ab