CVE-2017-17065
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
30/11/2017
Last modified:
20/04/2025
Description
An issue was discovered on D-Link DIR-605L Model B before FW2.11betaB06_hbrf devices, related to the code that handles the authentication values for HNAP. An attacker can cause a denial of service (device crash) or possibly have unspecified other impact by sending a sufficiently long string in the password field of the HTTP Basic Authentication section of the HTTP request.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
7.80
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:dlink:dir-605l_model_b_firmware:*:*:*:*:*:*:*:* | fw2.11betab06_hbrf (excluding) | |
| cpe:2.3:h:dlink:dir-605l_model_b:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



