An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilege account) access, an attacker can intercept the response from a POST request to obtain "Admin" rights due to the admin password being displayed in XML.
2018-08-29T19:29:00.267
2024-11-21T03:45:42.933
Modified
CVSSv3.0: 8.0 (HIGH)
AV:A/AC:L/Au:S/C:P/I:N/A:N
5.1
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | dlink | dir-601_firmware | 2.02na | Yes |
Hardware | dlink | dir-601 | - | No |