10
CVSSv2

CVE-2019-18852

Published: 11/11/2019 Updated: 24/08/2020
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_config/image_sign. This affects DIR-600 B1 V2.01 for WW, DIR-890L A1 v1.03, DIR-615 J1 v100 (for DCN), DIR-645 A1 v1.03, DIR-815 A1 v1.01, DIR-823 A1 v1.01, and DIR-842 C1 v3.00.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dlink dir-600_b1_firmware 2.01

dlink dir-615_j1_firmware 100

dlink dir-645_a1_firmware 1.03

dlink dir-815_a1_firmware 1.01

dlink dir-823_a1_firmware 1.01

dlink dir-842_c1_firmware 3.00

dlink dir-890l_a1_firmware 1.03