D-Link DIR-890L A2 Improper Access Control

Discussion in 'News Aggregator' started by Packet Storm, 3 Jul 2018.

  1. Packet Storm

    Packet Storm Guest

    An issue was discovered on D-Link DIR-890L A2 devices. Due to the predictability of the /docs/captcha_(number).jpeg URI, being local to the network, but unauthenticated to the administrator's panel, an attacker can disclose the CAPTCHAs used by the access point and can elect to load the CAPTCHA of their choosing, leading to unauthorized login attempts to the access point.

    Continue reading...
     

Share This Page

Loading...