CVE-2023-36089: Critical severity d-link dir-645 firmware vulnerability
UNSUPPORTED WHEN ASSIGNED Authentication Bypass vulnerability in D-Link DIR-645 firmware version 1.03 allows remote attackers to gain escalated privileges via function phpcgimain in cgibin. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-36089?
The severity of CVE-2023-36089 is critical with a CVSS score of 9.8.
How does the Authentication Bypass vulnerability in D-Link DIR-645 firmware version 1.03 (CVE-2023-36089) occur?
The vulnerability occurs through the function phpcgi_main in cgibin, allowing remote attackers to gain escalated privileges.
Which D-Link product and firmware version is affected by CVE-2023-36089?
The D-Link DIR-645 firmware version 1.03 is affected by CVE-2023-36089.
Is there a fix available for CVE-2023-36089?
Since the affected product is no longer supported, there may not be an official fix available. It is recommended to contact the maintainer or consider upgrading to a supported product.
Are there any additional references for CVE-2023-36089?
Additional references can be found in D-Link's security bulletin and support pages.