Description
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. The One Touch application discloses sensitive information, such as the hashed admin login password and the Internet provider connection username and cleartext password, in the application's response body for a /tmp/var/passwd or /tmp/home/wan_stat URI.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T15:19:09.311Z
Reserved: 2020-08-21T00:00:00.000Z
Link: CVE-2020-24577
No data.
Status : Modified
Published: 2021-01-08T07:15:11.810
Modified: 2024-11-21T05:15:02.047
Link: CVE-2020-24577
No data.
OpenCVE Enrichment
No data.
Weaknesses