First published: Tue May 27 2014(Updated: )
Multiple SQL injection vulnerabilities in the administration login page in D-Link DAP-1350 (Rev. A1) with firmware 1.14 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link DAP-1350 Firmware | <=1.14 | |
D-Link DAP-1350 Firmware | =1.10 | |
D-Link DAP-1350 | =rev._a1 | |
All of | ||
Any of | ||
D-Link DAP-1350 Firmware | <=1.14 | |
D-Link DAP-1350 Firmware | =1.10 | |
D-Link DAP-1350 | =rev._a1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3872 is classified as a medium severity vulnerability due to its potential for exploitation via remote SQL injection.
To mitigate CVE-2014-3872, update the D-Link DAP-1350 firmware to version 1.15 or later.
CVE-2014-3872 affects the D-Link DAP-1350 with firmware versions 1.14 and earlier, as well as version 1.10.
CVE-2014-3872 enables attackers to execute arbitrary SQL commands, compromising the security of the device.
Yes, CVE-2014-3872 can be exploited remotely through the administration login page, making it accessible from the internet.