CVE-2017-3192: Critical severity d-link dir-130 vulnerability
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials. The toolsadmin.asp page discloses the administrator password in base64 encoding in the returned web page. A remote attacker with access to this page (potentially through a authentication bypass such as CVE-2017-3191) may obtain administrator credentials for the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3192?
CVE-2017-3192 has a CVSS score indicating a medium severity vulnerability due to improper protection of administrator credentials.
How do I fix CVE-2017-3192?
To fix CVE-2017-3192, update the D-Link DIR-130 to firmware version 1.24 or newer and the DIR-330 to firmware version 1.13 or newer.
What systems are affected by CVE-2017-3192?
CVE-2017-3192 affects D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12.
What attack vector is utilized in CVE-2017-3192?
CVE-2017-3192 can be exploited remotely by attackers accessing the tools_admin.asp page.
What information is exposed by CVE-2017-3192?
CVE-2017-3192 exposes the administrator password in base64 encoding on the affected devices.