CVE-2002-1810
D-Link DWL-900AP+ Access Point 2.1 and 2.2 allows remote attackers to access the TFTP server without authentication and read the config.img file, which contains sensitive information such as the administrative password, the WEP encryption keys, and…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.75%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
D-Link DWL-900AP+ Access Point 2.1 and 2.2 allows remote attackers to access the TFTP server without authentication and read the config.img file, which contains sensitive information such as the administrative password, the WEP encryption keys, and network configuration information.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.75% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- dlink/dwl-900ap\+ firmware
- Source
- cve@mitre.org
References
- http://online.securityfocus.com/archive/1/296374Broken Link, Third Party Advisory, VDB Entry
- http://www.iss.net/security_center/static/10424.phpBroken Link
- http://www.securityfocus.com/bid/6015Broken Link, Third Party Advisory, VDB Entry
- http://online.securityfocus.com/archive/1/296374Broken Link, Third Party Advisory, VDB Entry
- http://www.iss.net/security_center/static/10424.phpBroken Link
- http://www.securityfocus.com/bid/6015Broken Link, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.