Lucene search

K
cve[email protected]CVE-2013-7004
HistoryDec 19, 2013 - 4:24 a.m.

CVE-2013-7004

2013-12-1904:24:57
CWE-255
web.nvd.nist.gov
17
d-link
dsr
firmware
hardcoded account
remote attackers
cve-2013-7004

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

9.2 High

AI Score

Confidence

High

0.013 Low

EPSS

Percentile

85.7%

D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 have a hardcoded account of username gkJ9232xXyruTRmY, which makes it easier for remote attackers to obtain access by leveraging knowledge of the username.

Affected configurations

NVD
Node
dlinkdsr-500_firmwareRange1.08b51
OR
dlinkdsr-500_firmwareMatch1.02b11
OR
dlinkdsr-500_firmwareMatch1.02b25
OR
dlinkdsr-500_firmwareMatch1.03b12
OR
dlinkdsr-500_firmwareMatch1.03b23
OR
dlinkdsr-500_firmwareMatch1.03b27
OR
dlinkdsr-500_firmwareMatch1.03b36
OR
dlinkdsr-500_firmwareMatch1.03b43
OR
dlinkdsr-500_firmwareMatch1.04b58
OR
dlinkdsr-500_firmwareMatch1.06b43
OR
dlinkdsr-500_firmwareMatch1.06b53
AND
dlinkdsr-500Match-
Node
dlinkdsr-150n_firmwareRange1.05b48
AND
dlinkdsr-150nMatch-
Node
dlinkdsr-250n_firmwareRange1.08b39
OR
dlinkdsr-250n_firmwareMatch1.01b46
OR
dlinkdsr-250n_firmwareMatch1.01b56
OR
dlinkdsr-250n_firmwareMatch1.05b20
OR
dlinkdsr-250n_firmwareMatch1.05b53
OR
dlinkdsr-250n_firmwareMatch1.08b31
AND
dlinkdsr-250nMatch-
Node
dlinkdsr-150_firmwareRange1.08b29
OR
dlinkdsr-150_firmwareMatch1.05b29
OR
dlinkdsr-150_firmwareMatch1.05b35
OR
dlinkdsr-150_firmwareMatch1.05b46
OR
dlinkdsr-150_firmwareMatch1.05b50
AND
dlinkdsr-150Match-
Node
dlinkdsr-500n_firmwareRange1.08b51
OR
dlinkdsr-500n_firmwareMatch1.02b11
OR
dlinkdsr-500n_firmwareMatch1.02b25
OR
dlinkdsr-500n_firmwareMatch1.03b12
OR
dlinkdsr-500n_firmwareMatch1.03b23
OR
dlinkdsr-500n_firmwareMatch1.03b27
OR
dlinkdsr-500n_firmwareMatch1.03b36
OR
dlinkdsr-500n_firmwareMatch1.03b43
OR
dlinkdsr-500n_firmwareMatch1.04b58
OR
dlinkdsr-500n_firmwareMatch1.06b43
OR
dlinkdsr-500n_firmwareMatch1.06b53
AND
dlinkdsr-500nMatch-
Node
dlinkdsr-1000n_firmwareRange1.08b51
OR
dlinkdsr-1000n_firmwareMatch1.01b50
OR
dlinkdsr-1000n_firmwareMatch1.02b11
OR
dlinkdsr-1000n_firmwareMatch1.02b25
OR
dlinkdsr-1000n_firmwareMatch1.03b12
OR
dlinkdsr-1000n_firmwareMatch1.03b23
OR
dlinkdsr-1000n_firmwareMatch1.03b27
OR
dlinkdsr-1000n_firmwareMatch1.03b36
OR
dlinkdsr-1000n_firmwareMatch1.03b43
OR
dlinkdsr-1000n_firmwareMatch1.04b58
OR
dlinkdsr-1000n_firmwareMatch1.06b43
OR
dlinkdsr-1000n_firmwareMatch1.06b53
AND
dlinkdsr-1000nMatch-
Node
dlinkdsr-250_firmwareRange1.08b39
OR
dlinkdsr-250_firmwareMatch1.01b46
OR
dlinkdsr-250_firmwareMatch1.01b56
OR
dlinkdsr-250_firmwareMatch1.05b20
OR
dlinkdsr-250_firmwareMatch1.05b53
OR
dlinkdsr-250_firmwareMatch1.08b31
AND
dlinkdsr-250Match-
Node
dlinkdsr-1000_firmwareRange1.08b51
OR
dlinkdsr-1000_firmwareMatch1.01b50
OR
dlinkdsr-1000_firmwareMatch1.02b11
OR
dlinkdsr-1000_firmwareMatch1.02b25
OR
dlinkdsr-1000_firmwareMatch1.03b12
OR
dlinkdsr-1000_firmwareMatch1.03b23
OR
dlinkdsr-1000_firmwareMatch1.03b27
OR
dlinkdsr-1000_firmwareMatch1.03b36
OR
dlinkdsr-1000_firmwareMatch1.03b43
OR
dlinkdsr-1000_firmwareMatch1.04b58
OR
dlinkdsr-1000_firmwareMatch1.06b43
OR
dlinkdsr-1000_firmwareMatch1.06b53
AND
dlinkdsr-1000Match-

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

9.2 High

AI Score

Confidence

High

0.013 Low

EPSS

Percentile

85.7%

Related for CVE-2013-7004