CVE-2019-7642 Information
Feb 14, 2021
cve
Description
D-Link routers with the mydlink feature have some web interfaces without authentication requirements. An attacker can remotely obtain users’ DNS query logs and login logs. Vulnerable targets include but are not limited to the latest firmware versions of DIR-817LW (A1-1.04) DIR-816L (B1-2.06) DIR-816 (B1-2.06?) DIR-850L (A1-1.09) and DIR-868L (A1-1.10).
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
https://github.com/xw77cve/CVE-2019-7642/blob/master/README.md
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
7.5
Share on: