CVE-2024-44408: Infoleak
D-Link DIR-823G v1.0.2B0520181207 is vulnerable to Information Disclosure. The device allows unauthorized configuration file downloads, and the downloaded configuration files contain plaintext user passwords.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-44408?
CVE-2024-44408 has been classified with a high severity due to the potential exposure of sensitive user credentials.
How does CVE-2024-44408 affect user security?
CVE-2024-44408 allows unauthorized users to download configuration files that contain plaintext user passwords, compromising user security.
How can I fix CVE-2024-44408?
To fix CVE-2024-44408, update the D-Link DIR-823G firmware to a version that addresses this vulnerability.
Is CVE-2024-44408 exploitable remotely?
Yes, CVE-2024-44408 can be exploited remotely, allowing attackers to access configuration files without physical access to the device.
Who is affected by CVE-2024-44408?
Anyone using the D-Link DIR-823G with firmware version 1.0.2B05_20181207 is affected by CVE-2024-44408.