CVE-2017-14422: High severity dlink dir-850l firmware vulnerability
D-Link DIR-850L REV. A (with firmware through FW114WWb07h2abbeta1) and REV. B (with firmware through FW208WWb02) devices use the same hardcoded /etc/stunnel.key private key across different customers' installations, which allows remote attackers to defeat the HTTPS cryptographic protection mechanisms by leveraging knowledge of this key from another installation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14422?
CVE-2017-14422 has a moderate severity rating due to its potential to undermine the HTTPS encryption of affected D-Link DIR-850L devices.
How do I fix CVE-2017-14422?
To address CVE-2017-14422, update your D-Link DIR-850L firmware to versions that are not vulnerable, specifically those beyond FW114WWb07_h2ab or FW208WWb02.
Which devices are affected by CVE-2017-14422?
CVE-2017-14422 affects D-Link DIR-850L Rev. A and Rev. B devices running specific vulnerable firmware versions.
What are the implications of CVE-2017-14422?
The implications of CVE-2017-14422 include the risk of remote attackers intercepting sensitive communications due to the use of a hardcoded private key.
When was CVE-2017-14422 discovered?
CVE-2017-14422 was discovered in September 2017, highlighting a significant security flaw in certain D-Link router firmware.