Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-13030


A vulnerability was found in D-Link DIR-823G 1.0.2B05_20181207. It has been rated as critical. This issue affects the function SetAutoRebootSettings/SetClientInfo/SetDMZSettings/SetFirewallSettings/SetParentsControlInfo/SetQoSSettings/SetVirtualServerSettings of the file /HNAP1/ of the component Web Management Interface. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.


Published

2024-12-30T01:15:06.060

Last Modified

2025-07-15T18:37:27.223

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.3 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-266
    CWE-284

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System dlink dir-823g_firmware 1.0.2b05_20181207 Yes
Hardware dlink dir-823g - No

References