CVE-2018-12710: High severity d-link dir-601 firmware vulnerability
Published Aug 29, 2018
·Updated
An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilege account) access, an attacker can intercept the response from a POST request to obtain "Admin" rights due to the admin password being displayed in XML.
Affected Software
2 affected components
Dlink Dir-601 Firmware=2.02na
Dlink Dir-601
Event History
Aug 29, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12710?
CVE-2018-12710 is considered to be of medium severity due to the potential for privilege escalation.
2
How do I fix CVE-2018-12710?
To fix CVE-2018-12710, update the D-Link DIR-601 firmware to a version that addresses this vulnerability.
3
Who is affected by CVE-2018-12710?
Users of D-Link DIR-601 devices running firmware version 2.02NA are affected by CVE-2018-12710.
4
What is the impact of CVE-2018-12710?
The impact of CVE-2018-12710 allows an attacker with local network access to gain unauthorized 'Admin' rights.
5
When was CVE-2018-12710 disclosed?
CVE-2018-12710 was disclosed in August 2018.