CVE-2019-18666
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
An issue was discovered on D-Link DAP-1360 revision F devices. Remote attackers can start a telnet service without authorization via an undocumented HTTP request. Although this is the primary vulnerability, the impact depends on the firmware version. Versions 609EU through 613EUbeta were tested. Versions through 6.12b01 have weak root credentials, allowing an attacker to gain remote root access. After 6.12b01, the root credentials were changed but the telnet service can still be started without authorization.
Se ha detectado un problema en los dispositivos D-Link DAP-1360 revision F. Los atacantes remotos pueden iniciar un servicio telnet sin autorización por medio de una petición HTTP no documentada. Aunque ésta es la principal vulnerabilidad, el impacto depende de la versión del firmware. Las versiones 609EU a 613EUbeta fueron probadas. Las versiones hasta la 6.12b01 contienen credenciales root débiles, permitiendo a un atacante conseguir acceso root remoto. Después de la versión 6.12b01, las credenciales root fueron cambiadas pero el servicio telnet todavía puede ser iniciado sin autorización.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-11-02 CVE Reserved
- 2020-05-15 CVE Published
- 2023-09-18 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-306: Missing Authentication for Critical Function
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
http://c1a.eu/dlink-dap-1360.html | 2024-08-05 | |
https://daschloer.github.io/sec/dlink-dap-1360.html | 2024-08-05 |
URL | Date | SRC |
---|---|---|
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10171 | 2023-04-26 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dlink Search vendor "Dlink" | Dap-1360 Revision F Firmware Search vendor "Dlink" for product "Dap-1360 Revision F Firmware" | <= 6.12b01 Search vendor "Dlink" for product "Dap-1360 Revision F Firmware" and version " <= 6.12b01" | - |
Affected
| in | Dlink Search vendor "Dlink" | Dap-1360 Revision F Search vendor "Dlink" for product "Dap-1360 Revision F" | - | - |
Safe
|