Vulnerability Report

CVE-2018-12103

Title: D-Link Dir-885\/R Broken Access Control

Broken Access Control

Proof Of Concept

No public PoC currently indexed for CVE-2018-12103.

CWE Category CWE-863
Published Date Jul 05, 2018
Modified Date Nov 21, 2024
Exploit Status Not Found
Score 6.5 CVSS v3.0
Exploit Probability (EPSS)
0.45%

Vulnerability Summary

CVE-2018-12103: An issue was discovered on D-Link DIR-890L with firmware 1.21B02beta01 and earlier, DIR-885L/R with firmware 1.21B03beta01 and earlier, and DIR-895L/R with firmware 1.21B04beta04 and earlier devices (all hardware revisions). Due to the predictability of the /docs/captcha_(number).jpeg URI, being local to the network, but unauthenticated to the administrator's panel, an attacker can disclose the CAPTCHAs used by the access point and can elect to load the CAPTCHA of their choosing, leading to unauthorized login attempts to the access point.

CVSS v3.0
Source Entity [email protected]
Severity MEDIUM
6.5
Attack Vector
ADJACENT_NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
UNCHANGED
RAW VECTOR CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v2.0
Source Entity [email protected]
Severity LOW
3.3
Access Vector
N/A
Authentication
N/A
RAW VECTOR AV:A/AC:L/Au:N/C:N/I:P/A:N

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2018-12103 Exploits & PoCs (Proof Of Concept)

No public PoCs found in our database for this CVE.

MODIFIED

Vulnerability data or affected products updated.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector ADJACENT_NETWORK
Complexity LOW
Privileges N/A
Interaction NONE
CVSS Vector String CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Stack

No specific products linked.