CVE-2017-14425: High severity dlink dir-850l firmware vulnerability
Published Sep 13, 2017
·Updated
D-Link DIR-850L REV. A (with firmware through FW114WWb07h2abbeta1) and REV. B (with firmware through FW208WWb02) devices have 0666 /var/etc/hnapasswd permissions.
Affected Software
6 affected components
Dlink Dir-850l Firmware<fw114wwb07_h2ab
Dlink Dir-850l Firmware=fw114wwb07_h2ab-beta1
Dlink DIR-850L
Dlink Dir-850l Firmware<=fw208wwb02
D-Link DIR-850L firmware<=fw114wwb07_h2ab
D-Link DIR-850L firmware<=fw208wwb02
Event History
Sep 13, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14425?
CVE-2017-14425 has a medium severity due to improper permissions allowing unauthorized access to sensitive files.
2
How do I fix CVE-2017-14425?
To fix CVE-2017-14425, update the D-Link DIR-850L firmware to the latest version that resolves the file permission issues.
3
Which D-Link DIR-850L firmware versions are affected by CVE-2017-14425?
CVE-2017-14425 affects firmware through FW114WWb07_h2ab_beta1 for REV. A models and through FW208WWb02 for REV. B models.
4
What devices are impacted by CVE-2017-14425?
CVE-2017-14425 impacts D-Link DIR-850L devices, specifically the REV. A and REV. B versions.
5
Is there a workaround for CVE-2017-14425 if I cannot update the firmware?
There is no specific workaround for CVE-2017-14425 other than updating to the patched firmware.