CVE-2017-14423: High severity dlink dir-850l firmware vulnerability
htdocs/parentalcontrols/bind.php on D-Link DIR-850L REV. A (with firmware through FW114WWb07h2abbeta1) devices does not prevent unauthenticated nonce-guessing attacks, which makes it easier for remote attackers to change the DNS configuration via a series of requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14423?
CVE-2017-14423 has a high severity rating due to its potential for remote exploitation.
How do I fix CVE-2017-14423?
To fix CVE-2017-14423, ensure your D-Link DIR-850L firmware is updated to a version beyond fw114wwb07_h2ab.
What devices are affected by CVE-2017-14423?
CVE-2017-14423 affects D-Link DIR-850L devices running firmware through version fw114wwb07_h2ab_beta1.
Can CVE-2017-14423 be exploited without authentication?
Yes, CVE-2017-14423 can be exploited without authentication due to nonce-guessing vulnerabilities.
What type of attack is associated with CVE-2017-14423?
CVE-2017-14423 is associated with unauthenticated nonce-guessing attacks that allow DNS configuration changes.