PoC Index

CVE-2019-7390

HIGH 8.6EPSS 2.0%

An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to hijack the DNS service configuration of all clients in the WLAN, without authentication, via the SetWanSettings HNAP API.

CVSS v3.0
8.6 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
1.96% chance of exploitation in the next 30 days, 79th percentile
Published
2019-02-05
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related