ID

VAR-E-201907-0200


CVE

cve_id:CVE-2019-1010156

Trust: 0.3

cve_id:CVE-2019-1010155

Trust: 0.3

sources: BID: 109351

TITLE

D-Link DSL-2750U Multiple Authentication Bypass Vulnerabilities

Trust: 0.3

sources: BID: 109351

DESCRIPTION

D-Link DSL-2750U is prone to multiple authentication-bypass vulnerabilities.
An attacker can exploit these issues to bypass authentication mechanism and perform unauthorized actions. This may lead to further attacks.
D-Link DSL-2750U Router 1.11 is vulnerable; other versions may also be affected.

Trust: 0.3

sources: BID: 109351

AFFECTED PRODUCTS

vendor:d linkmodel:dsl-2750uscope:eqversion:1.11

Trust: 0.3

sources: BID: 109351

EXPLOIT

The researcher has created a proof-of-concept to demonstrate these issues. Please see the references for more information.

Trust: 0.3

sources: BID: 109351

PRICE

Free

Trust: 0.3

sources: BID: 109351

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 109351

CREDITS

ADMIN_Joker

Trust: 0.3

sources: BID: 109351

EXTERNAL IDS

db:NVDid:CVE-2019-1010156

Trust: 0.3

db:NVDid:CVE-2019-1010155

Trust: 0.3

db:BIDid:109351

Trust: 0.3

sources: BID: 109351

REFERENCES

url:http://www.dlink.com/

Trust: 0.3

url:https://www.tenable.com/cve/cve-2019-1010155

Trust: 0.3

url:https://www.tenable.com/cve/cve-2019-1010156

Trust: 0.3

sources: BID: 109351

SOURCES

db:BIDid:109351

LAST UPDATE DATE

2022-07-27T09:58:15.990000+00:00


SOURCES UPDATE DATE

db:BIDid:109351date:2019-07-23T00:00:00

SOURCES RELEASE DATE

db:BIDid:109351date:2019-07-23T00:00:00