CVE-2014-7858

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
25/08/2017
Last modified:
20/04/2025

Description

The check_login function in D-Link DNR-326 before 2.10 build 03 allows remote attackers to bypass authentication and log in by setting the username cookie parameter to an arbitrary string.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:d-link:dnr-326_firmware:*:*:*:*:*:*:*:* 1.40b03 (including)
cpe:2.3:h:dlink:dnr-326:-:*:*:*:*:*:*:*