Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-18767


An issue was discovered in D-Link 'myDlink Baby App' version 2.04.06. Whenever actions are performed from the app (e.g., change camera settings or play lullabies), it communicates directly with the Wi-Fi camera (D-Link 825L firmware 1.08) with the credentials (username and password) in base64 cleartext. An attacker could conduct an MitM attack on the local network and very easily obtain these credentials.


Published

2018-12-20T23:29:00.863

Last Modified

2024-11-21T03:56:33.843

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 7.0 (HIGH)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

3.4

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-326

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dlink mydlink_baby_camera_monitor 2.04.06 Yes
Operating System d-link dcs-825l_firmware 1.08 Yes
Hardware dlink dcs-825l - No

References