VulnerabilityModified
CVE-2020-9376
D-Link DIR-610 devices allow Information Disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php.
HIGH 7.5EPSS 16.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 16.6%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
D-Link DIR-610 devices allow Information Disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 16.59% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74
- Affected
- dlink/dir-610 firmware
- Source
- cve@mitre.org
References
- https://gist.github.com/GouveaHeitor/dcbb67b301cc45adc00f8a6a2a0a590fExploit, Patch, Third Party Advisory
- https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10182Exploit, Vendor Advisory
- https://www.dlink.com.br/produto/dir-610/Product, Vendor Advisory
- https://gist.github.com/GouveaHeitor/dcbb67b301cc45adc00f8a6a2a0a590fExploit, Patch, Third Party Advisory
- https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10182Exploit, Vendor Advisory
- https://www.dlink.com.br/produto/dir-610/Product, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.