First published: Fri Dec 15 2017(Updated: )
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials. The tools_admin.asp page discloses the administrator password in base64 encoding in the returned web page. A remote attacker with access to this page (potentially through a authentication bypass such as CVE-2017-3191) may obtain administrator credentials for the device.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link DIR-130 firmware | =1.23 | |
Dlink Dir-130 | ||
D-link Dir-330 Firmware | =1.12 | |
Dlink Dir-330 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.