// For flags

CVE-2019-20213

 

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnconfig.php.

Los routers D-Link DIR-859 versiones anteriores a la versión v1.07b03_beta, permiten una divulgación de información no autenticada por medio del valor AUTHORIZED_GROUP=1%0a, como es demostrado por el archivo vpnconfig.php.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-01-02 CVE Reserved
  • 2020-01-02 CVE Published
  • 2023-11-08 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
  • CWE-863: Incorrect Authorization
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Dlink
Search vendor "Dlink"
Dir-859 Firmware
Search vendor "Dlink" for product "Dir-859 Firmware"
<= 1.05b03
Search vendor "Dlink" for product "Dir-859 Firmware" and version " <= 1.05b03"
-
Affected
in Dlink
Search vendor "Dlink"
Dir-859
Search vendor "Dlink" for product "Dir-859"
--
Safe
Dlink
Search vendor "Dlink"
Dir-859 Firmware
Search vendor "Dlink" for product "Dir-859 Firmware"
1.06b01
Search vendor "Dlink" for product "Dir-859 Firmware" and version "1.06b01"
beta1
Affected
in Dlink
Search vendor "Dlink"
Dir-859
Search vendor "Dlink" for product "Dir-859"
--
Safe
Dlink
Search vendor "Dlink"
Dir-822 Firmware
Search vendor "Dlink" for product "Dir-822 Firmware"
<= 2.03b01
Search vendor "Dlink" for product "Dir-822 Firmware" and version " <= 2.03b01"
-
Affected
in Dlink
Search vendor "Dlink"
Dir-822
Search vendor "Dlink" for product "Dir-822"
--
Safe
Dlink
Search vendor "Dlink"
Dir-822 Firmware
Search vendor "Dlink" for product "Dir-822 Firmware"
<= 3.12b04
Search vendor "Dlink" for product "Dir-822 Firmware" and version " <= 3.12b04"
-
Affected
in Dlink
Search vendor "Dlink"
Dir-822
Search vendor "Dlink" for product "Dir-822"
--
Safe
Dlink
Search vendor "Dlink"
Dir-823 Firmware
Search vendor "Dlink" for product "Dir-823 Firmware"
<= 1.00b06
Search vendor "Dlink" for product "Dir-823 Firmware" and version " <= 1.00b06"
-
Affected
in Dlink
Search vendor "Dlink"
Dir-823
Search vendor "Dlink" for product "Dir-823"
--
Safe
Dlink
Search vendor "Dlink"
Dir-865l Firmware
Search vendor "Dlink" for product "Dir-865l Firmware"
<= 1.07b01
Search vendor "Dlink" for product "Dir-865l Firmware" and version " <= 1.07b01"
-
Affected
in Dlink
Search vendor "Dlink"
Dir-865l
Search vendor "Dlink" for product "Dir-865l"
--
Safe
Dlink
Search vendor "Dlink"
Dir-868l Firmware
Search vendor "Dlink" for product "Dir-868l Firmware"
<= 1.12b04
Search vendor "Dlink" for product "Dir-868l Firmware" and version " <= 1.12b04"
-
Affected
in Dlink
Search vendor "Dlink"
Dir-868l
Search vendor "Dlink" for product "Dir-868l"
--
Safe
Dlink
Search vendor "Dlink"
Dir-868l Firmware
Search vendor "Dlink" for product "Dir-868l Firmware"
<= 2.05b02
Search vendor "Dlink" for product "Dir-868l Firmware" and version " <= 2.05b02"
-
Affected
in Dlink
Search vendor "Dlink"
Dir-868l
Search vendor "Dlink" for product "Dir-868l"
--
Safe
Dlink
Search vendor "Dlink"
Dir-869 Firmware
Search vendor "Dlink" for product "Dir-869 Firmware"
<= 1.03b02
Search vendor "Dlink" for product "Dir-869 Firmware" and version " <= 1.03b02"
-
Affected
in Dlink
Search vendor "Dlink"
Dir-869
Search vendor "Dlink" for product "Dir-869"
--
Safe
Dlink
Search vendor "Dlink"
Dir-880l Firmware
Search vendor "Dlink" for product "Dir-880l Firmware"
<= 1.08b04
Search vendor "Dlink" for product "Dir-880l Firmware" and version " <= 1.08b04"
-
Affected
in Dlink
Search vendor "Dlink"
Dir-880l
Search vendor "Dlink" for product "Dir-880l"
--
Safe
Dlink
Search vendor "Dlink"
Dir-890l Firmware
Search vendor "Dlink" for product "Dir-890l Firmware"
<= 1.11b01
Search vendor "Dlink" for product "Dir-890l Firmware" and version " <= 1.11b01"
-
Affected
in Dlink
Search vendor "Dlink"
Dir-890l
Search vendor "Dlink" for product "Dir-890l"
--
Safe
Dlink
Search vendor "Dlink"
Dir-890r Firmware
Search vendor "Dlink" for product "Dir-890r Firmware"
<= 1.11b01
Search vendor "Dlink" for product "Dir-890r Firmware" and version " <= 1.11b01"
-
Affected
in Dlink
Search vendor "Dlink"
Dir-890r
Search vendor "Dlink" for product "Dir-890r"
--
Safe
Dlink
Search vendor "Dlink"
Dir-885l Firmware
Search vendor "Dlink" for product "Dir-885l Firmware"
<= 1.12b05
Search vendor "Dlink" for product "Dir-885l Firmware" and version " <= 1.12b05"
-
Affected
in Dlink
Search vendor "Dlink"
Dir-885l
Search vendor "Dlink" for product "Dir-885l"
--
Safe
Dlink
Search vendor "Dlink"
Dir-885r Firmware
Search vendor "Dlink" for product "Dir-885r Firmware"
<= 1.12b05
Search vendor "Dlink" for product "Dir-885r Firmware" and version " <= 1.12b05"
-
Affected
in Dlink
Search vendor "Dlink"
Dir-885r
Search vendor "Dlink" for product "Dir-885r"
--
Safe
Dlink
Search vendor "Dlink"
Dir-895l Firmware
Search vendor "Dlink" for product "Dir-895l Firmware"
<= 1.12b10
Search vendor "Dlink" for product "Dir-895l Firmware" and version " <= 1.12b10"
-
Affected
in Dlink
Search vendor "Dlink"
Dir-895l
Search vendor "Dlink" for product "Dir-895l"
--
Safe
Dlink
Search vendor "Dlink"
Dir-895r Firmware
Search vendor "Dlink" for product "Dir-895r Firmware"
<= 1.12b10
Search vendor "Dlink" for product "Dir-895r Firmware" and version " <= 1.12b10"
-
Affected
in Dlink
Search vendor "Dlink"
Dir-895r
Search vendor "Dlink" for product "Dir-895r"
--
Safe
Dlink
Search vendor "Dlink"
Dir-818lx Firmware
Search vendor "Dlink" for product "Dir-818lx Firmware"
--
Affected
in Dlink
Search vendor "Dlink"
Dir-818lx
Search vendor "Dlink" for product "Dir-818lx"
--
Safe