CVE-2018-12710
Being local to the network and having only "User" account (which is a low privilege account) access, an attacker can intercept the response from a POST request to obtain "Admin" rights due to the admin password being displayed in XML.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 76.5%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilege account) access, an attacker can intercept the response from a POST request to obtain "Admin" rights due to the admin password being displayed in XML.
- CVSS 3.0
- 8.0 HIGHCVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 76.51% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-319
- Affected
- dlink/dir-601 firmware
- Source
- cve@mitre.org
References
- http://seclists.org/fulldisclosure/2018/Aug/45Mailing List, Third Party Advisory
- https://www.exploit-db.com/exploits/45306/Exploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2018/Aug/45Mailing List, Third Party Advisory
- https://www.exploit-db.com/exploits/45306/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.