Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query history.
2021-10-31T19:15:09.920
2024-11-21T06:08:34.327
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | d-link | dir-868lw_firmware | 1.12b | Yes |
Hardware | dlink | dir-868lw | - | No |