CVE-2017-14421: Critical severity dlink dir-850l firmware vulnerability
D-Link DIR-850L REV. B (with firmware through FW208WWb02) devices have a hardcoded password of wrgac25dlink.2013guidir850l for the Alphanetworks account upon device reset, which allows remote attackers to obtain root access via a TELNET session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14421?
CVE-2017-14421 is considered a high-severity vulnerability due to its potential for remote root access.
How do I fix CVE-2017-14421?
To fix CVE-2017-14421, update your D-Link DIR-850L firmware to a version later than FW208WWb02.
What devices are affected by CVE-2017-14421?
CVE-2017-14421 affects D-Link DIR-850L devices with firmware versions up to and including FW208WWb02.
Can CVE-2017-14421 be exploited remotely?
Yes, CVE-2017-14421 can be exploited remotely via a TELNET session due to the hardcoded password.
What should I do if I cannot update my D-Link DIR-850L firmware to fix CVE-2017-14421?
If you cannot update the firmware, it's essential to disable remote administration and secure the device as much as possible.