CVE-2018-17880
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
03/10/2018
Last modified:
26/04/2023
Description
On D-Link DIR-823G 2018-09-19 devices, the GoAhead configuration allows /HNAP1 RunReboot commands without authentication to trigger a reboot.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
7.80
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:d-link:dir-823g_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:dlink:dir-823g:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page