CVE-2019-15656

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
19/03/2020
Last modified:
17/11/2023

Description

D-Link DSL-2875AL and DSL-2877AL devices through 1.00.05 are prone to information disclosure via a simple crafted request to index.asp on the web management server because of username_v and password_v variables.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dlink:dsl-2875al_firmware:*:*:*:*:*:*:*:* 1.00.05 (including)
cpe:2.3:h:dlink:dsl-2875al:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dsl-2877al_firmware:*:*:*:*:*:*:*:* 1.00.05 (including)
cpe:2.3:h:dlink:dsl-2877al:-:*:*:*:*:*:*:*