Sploitus

CVE-2019-17506

No indexed exploits for CVE-2019-17506 yet

There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the router's username and password (and other information) via a DEVICE.ACCOUNT value for SERVICES in conjunction with AUTHORIZED_GROUP=1%0a to getcfg.php. This could be used to control the router remotely.

Dlink dir-868l b1 Firmware
= 2.03
Fix
Available
CVSS 2.0
10.0 HIGH
CVSS 3.1
9.8 CRITICAL
EPSS
57.3% (99th percentile)
Weakness
CWE-306
NVD status
Modified
Published
2019-10-11
CVE-2019-17506 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2019-17506 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2019-17506 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.