vendor:
DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router
by:
Gem George
9.8
CVSS
CRITICAL
Authentication Bypass
287
CWE
Product Name: DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router
Affected Version From: 1.02
Affected Version To: 2.06
Patch Exists: YES
Related CWE: CVE-2018-9032
CPE: h:d-link:dir-850l_wireless_ac1200_dual_band_gigabit_cloud_router
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Route Authentication Bypass
An authentication bypass vulnerability on D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router potentially allows attackers to bypass SharePort Web Access Portal by directly accessing authenticated pages such as /category_view.php or /folder_view.php. This could potentially allow unauthorized remote access of media stored in SharePort and may perform write operation in the portal.
Mitigation:
Ensure that authentication is properly enforced for all web pages.