CVE-2019-17505: High severity dlink dap-1320 a2 firmware vulnerability
D-Link DAP-1320 A2-V1.21 routers have some web interfaces without authentication requirements, as demonstrated by uplinkinfo.xml. An attacker can remotely obtain a user's Wi-Fi SSID and password, which could be used to connect to Wi-Fi or perform a dictionary attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-17505?
CVE-2019-17505 is considered a high-severity vulnerability due to the risk of unauthorized Wi-Fi access.
How do I fix CVE-2019-17505?
To mitigate CVE-2019-17505, update your D-Link DAP-1320 A2 router to the latest firmware version that addresses this vulnerability.
What impact does CVE-2019-17505 have on my device?
CVE-2019-17505 allows attackers to access sensitive information, such as Wi-Fi SSID and password, potentially leading to unauthorized network access.
Are there specific models affected by CVE-2019-17505?
CVE-2019-17505 specifically affects the D-Link DAP-1320 A2 router running firmware version 1.21.
Can I exploit CVE-2019-17505 without being on the same network?
Yes, CVE-2019-17505 can be exploited remotely, allowing attackers to obtain Wi-Fi credentials without being physically present on the network.