D-Link DIR-130 firmware version 1.23 and DIR-330 firmware...
Critical severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated May 5, 2023
Description
Published by the National Vulnerability Database
Dec 16, 2017
Published to the GitHub Advisory Database
May 13, 2022
Last updated
May 5, 2023
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page. A remote attacker that can access the remote management login page can manipulate the POST request in such a manner as to access some administrator-only pages such as tools_admin.asp without credentials.
References