First published: Sun Aug 28 2022(Updated: )
D-Link DIR845L A1 contains a authentication vulnerability via an AUTHORIZED_GROUP=1 value, as demonstrated by a request for getcfg.php.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link DIR-845L Firmware | >=1.0.0<=1.0.3 | |
D-Link DIR-845L | =a1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36755 is considered a high severity vulnerability due to the authentication bypass it allows.
To fix CVE-2022-36755, update the D-Link DIR845L firmware to the latest version that addresses this vulnerability.
CVE-2022-36755 affects D-Link DIR845L routers running firmware versions from 1.0.0 to 1.0.3.
CVE-2022-36755 can be exploited to gain unauthorized access to the router's configuration by bypassing authentication.
There are no effective workarounds for CVE-2022-36755 other than updating the affected firmware.