First published: Thu Mar 19 2020(Updated: )
D-Link DSL-2875AL devices through 1.00.05 are prone to password disclosure via a simple crafted /romfile.cfg request to the web management server. This request doesn't require any authentication and will lead to saving the configuration file. The password is stored in cleartext.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-link Dsl-2875al Firmware | <=1.00.05 | |
Dlink Dsl-2875al | ||
Dlink Dsl-2875al Firmware | <=1.00.05 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.