vendor:
DIR-615 T1
by:
Huzaifa Hussain
8.8
CVSS
HIGH
CAPTCHA Bypass
287
CWE
Product Name: DIR-615 T1
Affected Version From: DIR-615 T1 ver:20.10
Affected Version To: DIR-615 T1 ver:20.10
Patch Exists: YES
Related CWE: CVE-2019-17525
CPE: h:d-link:dir-615_t1:20.10
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2019
D-Link DIR-615 T1 20.10 – CAPTCHA Bypass
A vulnerability found on login-in page of D-LINK ROUTER "DIR-615" with "FIRMWARE VERSION:20.10" & "HARDWARE VERSION:T1" which allows attackers to easily bypass CAPTCHA on login page by BRUTEFORCING. Attackers can gain access to the router's administrative interface without having to enter the correct CAPTCHA.
Mitigation:
D-Link released new firmware designed to protect against logging in to the router using BRUTEFORCING.