CVE-2019-10042: High severity d-link dir-816l firmware vulnerability
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dirlogin.asp and use an API URL /goform/LoadDefaultSettings to reset the router without authentication.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-10042?
CVE-2019-10042 is a vulnerability in the D-Link DIR-816 A2 1.11 router that allows an attacker to reset the router without authentication.
How does CVE-2019-10042 work?
CVE-2019-10042 takes advantage of the router's failure to properly check the random token when authorizing a goform request, allowing an attacker to obtain the token from dir_login.asp and use an API URL to reset the router without authentication.
What is the severity of CVE-2019-10042?
CVE-2019-10042 has a severity rating of 7.5, which is considered high.
What software versions are affected by CVE-2019-10042?
The D-Link DIR-816 A2 1.11 router firmware version is affected by CVE-2019-10042.
How can I fix CVE-2019-10042?
To fix CVE-2019-10042, it is recommended to update the D-Link DIR-816 A2 router firmware to a version that addresses the vulnerability.