Description
Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_config/image_sign. This affects DIR-600 B1 V2.01 for WW, DIR-890L A1 v1.03, DIR-615 J1 v100 (for DCN), DIR-645 A1 v1.03, DIR-815 A1 v1.01, DIR-823 A1 v1.01, and DIR-842 C1 v3.00.
Published: 2019-11-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-8549 Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_config/image_sign. This affects DIR-600 B1 V2.01 for WW, DIR-890L A1 v1.03, DIR-615 J1 v100 (for DCN), DIR-645 A1 v1.03, DIR-815 A1 v1.01, DIR-823 A1 v1.01, and DIR-842 C1 v3.00.
History

No history.

Subscriptions

Dlink Dir-600 B1 Dir-600 B1 Firmware Dir-615 J1 Dir-615 J1 Firmware Dir-645 A1 Dir-645 A1 Firmware Dir-815 A1 Dir-815 A1 Firmware Dir-823 A1 Dir-823 A1 Firmware Dir-842 C1 Dir-842 C1 Firmware Dir-890l A1 Dir-890l A1 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T02:02:39.803Z

Reserved: 2019-11-11T00:00:00.000Z

Link: CVE-2019-18852

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-11-11T14:15:10.697

Modified: 2024-11-21T04:33:42.843

Link: CVE-2019-18852

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses