CVE-2015-7247: Infoleak
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and web account hashes (super and admin) in plaintext when running a configuration backup, which allows remote attackers to obtain sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7247?
CVE-2015-7247 is classified as a medium severity vulnerability due to the potential exposure of sensitive credentials.
How do I fix CVE-2015-7247?
To fix CVE-2015-7247, upgrade the D-Link DVG-N5402SP firmware to a version that does not expose sensitive information during configuration backups.
What information is exposed by CVE-2015-7247?
CVE-2015-7247 discloses usernames, passwords, keys, values, and web account hashes in plaintext.
Can CVE-2015-7247 be exploited remotely?
Yes, CVE-2015-7247 allows remote attackers to obtain sensitive information without authentication.
Which firmware versions are affected by CVE-2015-7247?
CVE-2015-7247 affects firmware versions W1000CN-00, W1000CN-03, and W2000EN-00 of the D-Link DVG-N5402SP.