CVE-2018-8898: Critical severity Dlink Dsl-3782 Firmware vulnerability
A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1WI20170303 || SWVer="V100R001B012" FWVer="3.10.0.24" FirmVer="TT77616E6771696F6E67") allows unauthenticated attackers to perform arbitrary modification (read, write) to passwords and configurations meanwhile an administrator is logged into the web panel.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to the D-Link DSL-3782 Login Panel web UI so unauthenticated users cannot reach the router’s authentication mechanism while an administrator is logged in.
Event History
Frequently Asked Questions
What is the vulnerability ID for this flaw?
The vulnerability ID is CVE-2018-8898.
What is the severity level of CVE-2018-8898?
CVE-2018-8898 has a severity level of critical.
Which software is affected by CVE-2018-8898?
The D-Link DSL-3782 router with firmware version 3.10.0.24 is affected by CVE-2018-8898.
What can an unauthenticated attacker do with this vulnerability?
An unauthenticated attacker can perform arbitrary modification (read, write) to passwords and configurations.
Are there any known exploits for CVE-2018-8898?
Yes, there are known exploits for CVE-2018-8898. You can find more information on them in the provided references.