First published: Tue Feb 05 2019(Updated: )
An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to hijack the DNS service configuration of all clients in the WLAN, without authentication, via the SetWanSettings HNAP API.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-823g Firmware | =1.02b03 | |
Dlink Dir-823g |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-7390.
The title of the vulnerability is 'An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03'.
The vulnerability allows remote attackers to hijack the DNS service configuration of all clients in the WLAN without authentication.
The severity of CVE-2019-7390 is high with a CVSS score of 8.6.
To fix CVE-2019-7390, update the firmware of the D-Link DIR-823G device to version 1.02B04 or later.