CVE-2023-26615: High severity d-link dir-823g firmware vulnerability
Published Jun 28, 2023
·Updated
D-Link DIR-823G firmware version 1.02B05 has a password reset vulnerability, which originates from the SetMultipleActions API, allowing unauthorized attackers to reset the WEB page management password.
Affected Software
2 affected components
Dlink Dir-823g Firmware=1.02b05
Dlink Dir-823g
Event History
Jun 28, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-26615?
CVE-2023-26615 is a password reset vulnerability in D-Link DIR-823G firmware version 1.02B05.
2
How does the password reset vulnerability in D-Link DIR-823G firmware version 1.02B05 work?
The vulnerability originates from the SetMultipleActions API, allowing unauthorized attackers to reset the WEB page management password.
3
What is the severity of CVE-2023-26615?
CVE-2023-26615 has a severity of 7.5 (high).
4
Is D-Link DIR-823G firmware version 1.02B05 vulnerable?
Yes, D-Link DIR-823G firmware version 1.02B05 is vulnerable to CVE-2023-26615.
5
How can I fix the password reset vulnerability in D-Link DIR-823G firmware version 1.02B05?
There is currently no official fix or patch available for CVE-2023-26615. It is recommended to update to the latest firmware version when it becomes available.