First published: Thu Mar 19 2020(Updated: )
D-Link DSL-2875AL and DSL-2877AL devices through 1.00.05 are prone to information disclosure via a simple crafted request to index.asp on the web management server because of username_v and password_v variables.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-link Dsl-2875al Firmware | <=1.00.05 | |
Dlink Dsl-2875al | ||
D-link Dsl-2877al Firmware | <=1.00.05 | |
Dlink Dsl-2877al | ||
Dlink Dsl-2875al Firmware | <=1.00.05 | |
Dlink Dsl-2877al Firmware | <=1.00.05 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15656 has a high severity due to its potential for information disclosure.
To fix CVE-2019-15656, upgrade the affected D-Link DSL-2875AL or DSL-2877AL devices to a firmware version later than 1.00.05.
CVE-2019-15656 affects D-Link DSL-2875AL and DSL-2877AL devices running firmware version 1.00.05 or earlier.
CVE-2019-15656 is classified as an information disclosure vulnerability that allows unauthorized access to sensitive information.
Yes, CVE-2019-15656 can be exploited remotely by sending a crafted request to the web management server.