An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It has a misconfigured FTP service that allows a malicious network user to access system folders and download sensitive files (such as the password hash file).
2020-12-22T19:15:13.190
2024-11-21T05:15:02.217
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:A/AC:L/Au:N/C:P/I:N/A:N
6.5
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | dlink | dsl2888a_firmware | < au_2.31_v1.1.47ae55 | Yes |
Hardware | dlink | dsl2888a | - | No |