CVE-2018-8898
Description
A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B012" FWVer="3.10.0.24" FirmVer="TT_77616E6771696F6E67") allows unauthenticated attackers to perform arbitrary modification (read, write) to passwords and configurations meanwhile an administrator is logged into the web panel.
In plain language
AI Worth attentionIf you use a D-Link DSL-3782 router, attackers can change or delete admin passwords and router settings when someone is logged into the router’s web panel—so you should act, especially if your router is reachable from the network.
In CVE-2018-8898, an authentication weakness (CWE-287) in the Login Panel of D-Link DSL-3782 allows a network attacker to read/modify/delete admin passwords and system settings without valid credentials while an administrator session is active in the web management panel.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-8898 and every CVE in our database. Create a free account — no credit card required.
Create Free Account