CVE-2015-7247
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and web account hashes (super and admin) in plaintext when running a configuration backup, which allows remote attackers to obtain sensitive information.
Published
2017-04-24T18:59:00.240
Last Modified
2025-04-20T01:37:25.860
Status
Deferred
Source
[email protected]
Severity
CVSSv3.0: 9.8 (CRITICAL)
CVSSv2 Vector
AV:N/AC:L/Au:N/C:C/I:N/A:N
- Access Vector: NETWORK
- Access Complexity: LOW
- Authentication: NONE
- Confidentiality Impact: COMPLETE
- Integrity Impact: NONE
- Availability Impact: NONE
Exploitability Score
10.0
Impact Score
6.9
Weaknesses
Affected Vendors & Products
References
-
http://packetstormsecurity.com/files/135590/D-Link-DVG-N5402SP-Path-Traversal-Information-Disclosure.html
Exploit, Third Party Advisory, VDB Entry
([email protected])
-
http://seclists.org/fulldisclosure/2016/Feb/24
Exploit, Third Party Advisory, VDB Entry
([email protected])
-
https://www.exploit-db.com/exploits/39409/
Exploit, Third Party Advisory, VDB Entry
([email protected])
-
http://packetstormsecurity.com/files/135590/D-Link-DVG-N5402SP-Path-Traversal-Information-Disclosure.html
Exploit, Third Party Advisory, VDB Entry
(af854a3a-2127-422b-91ae-364da2661108)
-
http://seclists.org/fulldisclosure/2016/Feb/24
Exploit, Third Party Advisory, VDB Entry
(af854a3a-2127-422b-91ae-364da2661108)
-
https://www.exploit-db.com/exploits/39409/
Exploit, Third Party Advisory, VDB Entry
(af854a3a-2127-422b-91ae-364da2661108)