CVE-2014-7858: Critical severity d-link dnr-326 vulnerability
Published Aug 25, 2017
·Updated
The checklogin function in D-Link DNR-326 before 2.10 build 03 allows remote attackers to bypass authentication and log in by setting the username cookie parameter to an arbitrary string.
Affected Software
2 affected components
D-Link Dnr-326 Firmware<=1.40b03
Dlink Dnr-326
Event History
Aug 25, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-7858?
CVE-2014-7858 is classified as a high severity vulnerability due to its potential for remote authentication bypass.
2
How do I fix CVE-2014-7858?
To fix CVE-2014-7858, upgrade the D-Link DNR-326 firmware to version 2.10 build 03 or later.
3
What type of attack is CVE-2014-7858 associated with?
CVE-2014-7858 is associated with remote attacks that exploit authentication bypass vulnerabilities.
4
Which devices are affected by CVE-2014-7858?
CVE-2014-7858 affects D-Link DNR-326 firmware versions up to and including 1.40b03.
5
Can CVE-2014-7858 be exploited over the internet?
Yes, CVE-2014-7858 can be exploited by remote attackers over the internet due to the nature of the authentication bypass.