CVE-2017-14424: High severity dlink dir-850l firmware vulnerability
D-Link DIR-850L REV. A (with firmware through FW114WWb07h2abbeta1) and REV. B (with firmware through FW208WWb02) devices have 0666 /var/passwd permissions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14424?
CVE-2017-14424 is considered a high-severity vulnerability due to the insecure permissions on the /var/passwd file.
How do I fix CVE-2017-14424?
To fix CVE-2017-14424, update the D-Link DIR-850L firmware to the latest secure version that addresses this issue.
What devices are affected by CVE-2017-14424?
CVE-2017-14424 affects D-Link DIR-850L devices with firmware up to 114WWb07_h2ab_beta1 for REV. A and up to 208WWb02 for REV. B.
What are the implications of CVE-2017-14424?
The implications of CVE-2017-14424 include potential unauthorized access to sensitive system files due to improper file permissions.
Is CVE-2017-14424 exploitable remotely?
Yes, CVE-2017-14424 is potentially exploitable remotely if the vulnerable firmware is exposed to the internet.