D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices use the same hardcoded /etc/stunnel.key private key across different customers' installations, which allows remote attackers to defeat the HTTPS cryptographic protection mechanisms by leveraging knowledge of this key from another installation.
2017-09-13T17:29:00.573
2025-04-20T01:37:25.860
Deferred
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | dlink | dir-850l_firmware | < fw114wwb07_h2ab | Yes |
Operating System | dlink | dir-850l_firmware | fw114wwb07_h2ab | Yes |
Hardware | dlink | dir-850l | - | No |
Operating System | dlink | dir-850l_firmware | ≤ fw208wwb02 | Yes |
Hardware | dlink | dir-850l | - | No |