V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2019-18852
CVE
Critical

Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_confi…

CVSS
9.8
Critical
EPSS
0.02
p71
Published
2019-01-01
Updated
2019-01-01
Description

Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_config/image_sign. This affects DIR-600 B1 V2.01 for WW, DIR-890L A1 v1.03, DIR-615 J1 v100 (for DCN), DIR-645 A1 v1.03, DIR-815 A1 v1.01, DIR-823 A1 v1.01, and DIR-842 C1 v3.00.

Tags · CWE
Pre-auth
CWE-319
CAPEC-65
CAPEC-102
CAPEC-117
CAPEC-383
CAPEC-477
Affected products
Dir-600_b1_firmwareDir-615_j1_firmwareDir-645_a1_firmwareDir-815_a1_firmwareDir-823_a1_firmwareDir-842_c1_firmwareDir-890l_a1_firmware
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2019-01-01
Published
2019-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.015 · p71
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-65 · CWE-319
└ via CAPEC-383 · CWE-319
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
dir-600_b1_firmware*Tracked
dir-615_j1_firmware*Tracked
dir-645_a1_firmware*Tracked
dir-815_a1_firmware*Tracked
dir-823_a1_firmware*Tracked
dir-842_c1_firmware*Tracked
dir-890l_a1_firmware*Tracked
Source databases
CVE
Related vulnerabilities