CVE-2020-15894: High severity d-link dir-816l firmware vulnerability
An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. There exists an exposed administration function in getcfg.php, which can be used to call various services. It can be utilized by an attacker to retrieve various sensitive information, such as admin login credentials, by setting the value of POSTSERVICES in the query string to DEVICE.ACCOUNT.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-15894?
CVE-2020-15894 is a vulnerability found in D-Link DIR-816L devices 2.x before 1.10b04Beta02, which allows an attacker to retrieve sensitive information.
How can an attacker exploit CVE-2020-15894?
An attacker can exploit CVE-2020-15894 by utilizing the exposed administration function in getcfg.php to call various services and retrieve sensitive information.
What is the severity of CVE-2020-15894?
CVE-2020-15894 has a severity rating of 7.5 (high).
How do I know if my device is affected by CVE-2020-15894?
If you are using D-Link DIR-816L devices 2.x before 1.10b04Beta02 or 2.06 firmware, your device may be affected by CVE-2020-15894.
How can I fix CVE-2020-15894?
To fix CVE-2020-15894, it is recommended to update your D-Link DIR-816L device to firmware version 1.10b04Beta02 or newer.