CVE-2022-43621: D-Link DIR-1935 HNAP Incorrect Comparison Authentication Bypass Vulnerability
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-1935 1.03 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP login requests. The issue results from an incorrectly implemented comparison. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-16152.
Other sources
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-1935 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP login requests. The issue results from an incorrectly implemented comparison. An attacker can leverage this vulnerability to bypass authentication on the system.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this D-Link router vulnerability?
The vulnerability ID of this D-Link router vulnerability is CVE-2022-43621.
What is the severity rating of CVE-2022-43621?
CVE-2022-43621 has a severity rating of 8.8 (high).
How can network-adjacent attackers exploit this vulnerability?
Network-adjacent attackers can bypass authentication on affected installations of D-Link DIR-1935 1.03 routers without requiring authentication.
What is the specific flaw that causes this vulnerability?
The specific flaw is an incorrect comparison within the handling of HNAP login requests.
Which D-Link router model and firmware versions are affected by this vulnerability?
This vulnerability affects D-Link DIR-1935 1.02, 1.03-b1, and 1.03-b2 firmware versions.