MEDIUM
D-Link DIR-878 HTTP POST Request dllog.cgi information disclosure
Published Jan 15, 2025
6.9
MEDIUMCVSS 4.0
EPSS 1.41%
Description
A vulnerability classified as problematic has been found in D-Link DIR-878 1.03. Affected is an unknown function of the file /dllog.cgi of the component HTTP POST Request Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected products
-
- Version 1.03StatusaffectedConstraints-
- Version
AND
- 1.03
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-1704 Advisory
- https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Unauthorized_Vulnerability/D-Link/DIR-878/dllog.md exploitBroken Link
- https://vuldb.com/?ctiid.291924 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.291924 vdb-entryThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.475011 third-party-advisoryThird Party AdvisoryVDB Entry
- https://www.dlink.com/ product
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-1704 | Advisory | |
| https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Unauthorized_Vulnerability/D-Link/DIR-878/dllog.md | exploitBroken Link | |
| https://vuldb.com/?ctiid.291924 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.291924 | vdb-entryThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.475011 | third-party-advisoryThird Party AdvisoryVDB Entry | |
| https://www.dlink.com/ | product |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Jan 15, 2025
Updated Jan 15, 2025
Reserved Jan 15, 2025
Link CVE-2025-0481
CISA Vulnrichment
Updated Jan 15, 2025
ENISA EUVD
EUVD-2025-1704 Assigner VulDB
Published Jan 15, 2025
Updated Jan 15, 2025
Exploited since n/a
Link EUVD-2025-1704