First published: Mon Jan 09 2017(Updated: )
D-Link DGS-1100 devices with Rev.B firmware 1.01.018 have a hardcoded SSL private key, which allows man-in-the-middle attackers to spoof devices by hijacking an HTTPS session.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link DGS-1100 Firmware | =1.01.018 | |
D-Link DGS-1100-05 | ||
D-Link DGS-1100-05PD | ||
D-Link DGS-1100-08 | ||
D-Link DGS-1100-08P | ||
D-Link DGS-1100-10MP | ||
D-Link DGS-1100-10MP | ||
D-Link DGS-1100-16 | ||
D-Link DGS-1100-18 | ||
D-Link DGS-1100-24 | ||
D-Link DGS-1100-24P | ||
D-Link DGS-1100-26 | ||
D-Link DGS-1100-26MP | ||
All of | ||
D-Link DGS-1100 Firmware | =1.01.018 | |
Any of | ||
D-Link DGS-1100-05 | ||
D-Link DGS-1100-05PD | ||
D-Link DGS-1100-08 | ||
D-Link DGS-1100-08P | ||
D-Link DGS-1100-10MP | ||
D-Link DGS-1100-10MP | ||
D-Link DGS-1100-16 | ||
D-Link DGS-1100-18 | ||
D-Link DGS-1100-24 | ||
D-Link DGS-1100-24P | ||
D-Link DGS-1100-26 | ||
D-Link DGS-1100-26MP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10125 is considered a high severity vulnerability due to the potential for man-in-the-middle attacks.
To mitigate CVE-2016-10125, update the D-Link DGS-1100 devices to the latest firmware version that addresses the hardcoded SSL private key issue.
CVE-2016-10125 affects D-Link DGS-1100 devices with Rev.B firmware version 1.01.018.
CVE-2016-10125 allows attackers to perform man-in-the-middle attacks by hijacking an HTTPS session.
Hardcoded SSL private key vulnerabilities like CVE-2016-10125 are a known security risk that can severely compromise network communications.