CVE-2017-14420: Medium severity dlink dir-850l firmware vulnerability
The D-Link NPAPI extension, as used on D-Link DIR-850L REV. A (with firmware through FW114WWb07h2abbeta1) and REV. B (with firmware through FW208WWb02) devices, does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14420?
CVE-2017-14420 is considered a high severity vulnerability due to the potential for man-in-the-middle attacks.
How do I fix CVE-2017-14420?
To fix CVE-2017-14420, you should update the firmware of your D-Link DIR-850L devices to the latest version available.
Which devices are affected by CVE-2017-14420?
CVE-2017-14420 affects D-Link DIR-850L REV. A and REV. B devices with specific vulnerable firmware versions.
What is the impact of CVE-2017-14420?
The impact of CVE-2017-14420 includes the ability for attackers to spoof SSL servers and potentially intercept sensitive information.
Can CVE-2017-14420 be exploited remotely?
Yes, CVE-2017-14420 can be exploited remotely, allowing attackers to conduct man-in-the-middle attacks without physical access.