Lucene search

K
cve[email protected]CVE-2005-1680
HistoryMay 25, 2005 - 4:00 a.m.

CVE-2005-1680

2005-05-2504:00:00
web.nvd.nist.gov
20
d-link
dsl
authentication bypass
cgi
firmwarecfg
remote attack

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7 High

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

77.2%

D-Link DSL-502T, DSL-504T, DSL-562T, and DSL-G604T, when /cgi-bin/firmwarecfg is executed, allows remote attackers to bypass authentication (1) if their IP address already exists in /var/tmp/fw_ip or (2) if their request is the first, which causes /var/tmp/fw_ip to be created and contain their IP address.

Affected configurations

NVD
Node
d-linkdsl-502t
OR
d-linkdsl-504t
OR
d-linkdsl-562t
OR
d-linkdsl-g604t

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7 High

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

77.2%

Related for CVE-2005-1680