CVE-2022-29332
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
17/05/2022
Last modified:
26/05/2022
Description
D-LINK DIR-825 AC1200 R2 is vulnerable to Directory Traversal. An attacker could use the "../../../../" setting of the FTP server folder to set the router's root folder for FTP access. This allows you to access the entire router file system via the FTP server.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:dlink:dir-825_firmware:2022.01.13-13.48:*:*:*:*:*:*:* | ||
cpe:2.3:h:dlink:dir-825:r2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page