CVE-2019-8392: High severity d-link dir-823g firmware vulnerability
Published Feb 17, 2019
·Updated
An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to enable Guest Wi-Fi via the SetWLanRadioSettings HNAP API to the web service provided by /bin/goahead.
Affected Software
4 affected components
Dlink Dir-823g Firmware=1.02b03
Dlink Dir-823g
All of the following
Dlink Dir-823g Firmware=1.02b03
Dlink Dir-823g
Event History
Feb 17, 2019
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Data Sourced
via NVD·04:29 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue on D-Link DIR-823G devices?
The vulnerability ID for this issue on D-Link DIR-823G devices is CVE-2019-8392.
2
What is the severity level of CVE-2019-8392?
CVE-2019-8392 has a severity level of high.
3
How can attackers exploit CVE-2019-8392?
Attackers can exploit CVE-2019-8392 by using incorrect access control to enable Guest Wi-Fi via the SetWLanRadioSettings HNAP API to the web service provided by /bin/goahead.
4
Which devices are affected by CVE-2019-8392?
D-Link DIR-823G devices with firmware 1.02B03 are affected by CVE-2019-8392.
5
Is D-Link DIR-823G firmware version 1.02B03 vulnerable to CVE-2019-8392?
Yes, D-Link DIR-823G firmware version 1.02B03 is vulnerable to CVE-2019-8392.