CVE-2017-14419: Medium severity dlink dir-850l firmware vulnerability
The D-Link NPAPI extension, as used on D-Link DIR-850L REV. A (with firmware through FW114WWb07h2abbeta1) and REV. B (with firmware through FW208WWb02) devices, participates in mydlink Cloud Services by establishing a TCP relay service for HTTP, even though a TCP relay service for HTTPS is also established.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14419?
CVE-2017-14419 has been classified as a moderate severity vulnerability.
How do I fix CVE-2017-14419?
To fix CVE-2017-14419, update the D-Link DIR-850L firmware to a version that is not affected by this vulnerability.
What devices are affected by CVE-2017-14419?
The D-Link DIR-850L REV. A and REV. B devices with specific firmware versions are affected by CVE-2017-14419.
What type of vulnerability is CVE-2017-14419?
CVE-2017-14419 is a vulnerability related to the use of an insecure TCP relay service for HTTP.
What are the consequences of CVE-2017-14419?
Exploitation of CVE-2017-14419 could allow attackers to intercept or manipulate unencrypted HTTP traffic.