D-Link DSL-504T stores usernames and passwords in cleartext in the router configuration file, which allows remote attackers to obtain sensitive information.
📦
dsl-504t
Vendor: d-link
Actively Exploited
0
CISA KEV List
PoC / Exploits
1
Code Available
Total RCEs
0
Remote Access
Total CVEs
2
Total Indexed
Avg. EPSS
7.40%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
7.5
CVSS
Severity: HIGH
7.5
CVSS
CVE-2005-1827
Exploit Found
D-Link DSL-504T allows remote attackers to bypass authentication and gain privileges, such as upgrade firmware, restart the router or restore a saved configuration, via a direct request to firmwarecfg.
Severity: HIGH
7.5
CVSS
D-Link DSL-502T, DSL-504T, DSL-562T, and DSL-G604T, when /cgi-bin/firmwarecfg is executed, allows remote attackers to bypass authentication (1) if their IP address already exists in /var/tmp/fw_ip or (2) if their request is the first, which causes /var/tmp/fw_ip to be created and contain their IP address.
Severity: HIGH