vendor:
DVG-N5402SP Web Management
by:
Karn Ganeshen
8,8
CVSS
HIGH
Path Traversal, Weak Credentials Management, and Sensitive Info Leakage
22, 522, 200
CWE
Product Name: DVG-N5402SP Web Management
Affected Version From: W1000CN-00
Affected Version To: W2000EN-00
Patch Exists: YES
Related CWE: CVE-2015-7245 + CVE-2015-7246 + CVE-2015-7247
CPE: h:dlink:dvg-n5402sp
Metasploit:
N/A
Other Scripts:
N/A
Tags: cve,cve2015,dlink,lfi,packetstorm,edb
CVSS Metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Nuclei Metadata: {'max-request': 1, 'vendor': 'd-link', 'product': 'dvg-n5402sp_firmware'}
Platforms Tested: ZS
2015
DLink DVGN5402SP Multiple Vulnerabilities
D-Link DVG-N5402SP is susceptible to local file inclusion in products with firmware W1000CN-00, W1000CN-03, or W2000EN-00. A remote attacker can read sensitive information via a .. (dot dot) in the errorpage parameter.
Mitigation:
Ensure that authentication is required to access the device file system.