CVE-2020-15894

CVE-2020-15894

An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. There exists an exposed administration function in getcfg.php, which can be used to call various services. It can be utilized by an attacker to retrieve various sensitive information, such as admin login credentials, by setting the value of _POST_SERVICES in the query string to DEVICE.ACCOUNT.

Source: CVE-2020-15894

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다