CVE-2018-12710
29.08.2018, 19:29
An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilege account) access, an attacker can intercept the response from a POST request to obtain "Admin" rights due to the admin password being displayed in XML.Enginsight
Vendor | Product | Version |
---|---|---|
dlink | dir-601_firmware | 2.02na:na |
𝑥
= Vulnerable software versions
Common Weakness Enumeration