CVE-2019-7390: High severity d-link dir-823g firmware vulnerability
Published Feb 5, 2019
·Updated
An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to hijack the DNS service configuration of all clients in the WLAN, without authentication, via the SetWanSettings HNAP API.
Affected Software
4 affected components
All of the following
Dlink Dir-823g Firmware=1.02b03
Dlink Dir-823g
Dlink Dir-823g Firmware=1.02b03
Dlink Dir-823g
Event History
Feb 5, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·12:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-7390.
2
What is the title of the vulnerability?
The title of the vulnerability is 'An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03'.
3
What is the description of the vulnerability?
The vulnerability allows remote attackers to hijack the DNS service configuration of all clients in the WLAN without authentication.
4
How severe is CVE-2019-7390?
The severity of CVE-2019-7390 is high with a CVSS score of 8.6.
5
How can I fix CVE-2019-7390?
To fix CVE-2019-7390, update the firmware of the D-Link DIR-823G device to version 1.02B04 or later.