755
VMScore

CVE-2018-8898

Published: 23/05/2018 Updated: 26/04/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B012" FWVer="3.10.0.24" FirmVer="TT_77616E6771696F6E67") allows unauthenticated malicious users to perform arbitrary modification (read, write) to passwords and configurations meanwhile an administrator is logged into the web panel.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dlink dsl-3782_firmware 3.10.0.24

Exploits

# Exploit Title: D-Link DSL 3782 - Authentication Bypass # Vendor Homepage: eudlinkcom # Version: A1_WI_20170303 || SWVer="V100R001B012" FWVer="310024" FirmVer="TT_77616E6771696F6E67" # Category: Webapps # Exploit Author: Giulio Comi # CVE : CVE-2018-8898 # Date: 20/05/2018 # Description # The web panel of D-Link DSL 3782 version (A1_ ...
D-Link DSL-3782 suffers from an authentication bypass vulnerability ...