D-Link DGS-1100 devices with Rev.B firmware 1.01.018 have a hardcoded SSL private key, which allows man-in-the-middle attackers to spoof devices by hijacking an HTTPS session.
2017-01-09T17:59:00.130
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 8.1 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | dlink | dgs-1100_firmware | 1.01.018 | Yes |
Hardware | dlink | dgs-1100-05 | - | No |
Hardware | dlink | dgs-1100-05pd | - | No |
Hardware | dlink | dgs-1100-08 | - | No |
Hardware | dlink | dgs-1100-08p | - | No |
Hardware | dlink | dgs-1100-10mp | - | No |
Hardware | dlink | dgs-1100-10mpp | - | No |
Hardware | dlink | dgs-1100-16 | - | No |
Hardware | dlink | dgs-1100-18 | - | No |
Hardware | dlink | dgs-1100-24 | - | No |
Hardware | dlink | dgs-1100-24p | - | No |
Hardware | dlink | dgs-1100-26 | - | No |
Hardware | dlink | dgs-1100-26mp | - | No |