vendor:
DIR850
by:
Ahmed Alroky
7.5
CVSS
HIGH
Insecure Access Control
287
CWE
Product Name: DIR850
Affected Version From: ET850-1.08TRb03
Affected Version To: ET850-1.08TRb03
Patch Exists: YES
Related CWE: CVE-2021-46378
CPE: h:dlink:dir850
Platforms Tested:
2022
DLINK DIR850 – Insecure Access Control
Visiting http://<IP Address>/config.dat allows access to the configuration file without authentication.
Mitigation:
Ensure that access to the configuration file is restricted to authenticated users.