CVE-2018-17777

CRITICALCVSS 9.8/10EPSS 1.87%

Last modified

CVE-2018-17777 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An issue was discovered on D-Link DVA-5592 A1_WI_20180823 devices. If the PIN of the page "/ui/cbpc/login" is the default Parental Control PIN (0000), it is possible to bypass the login form by editing the path of the cookie "sid" generated by the page. EPSS estimates a 1.87% chance of exploitation in the next 30 days.

Description

An issue was discovered on D-Link DVA-5592 A1_WI_20180823 devices. If the PIN of the page "/ui/cbpc/login" is the default Parental Control PIN (0000), it is possible to bypass the login form by editing the path of the cookie "sid" generated by the page. The attacker will have access to the router control panel with administrator privileges.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
1.87%

76.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
DlinkDva-5592 Firmwarea1_wi_20180823

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-17777?
An issue was discovered on D-Link DVA-5592 A1_WI_20180823 devices. If the PIN of the page "/ui/cbpc/login" is the default Parental Control PIN (0000), it is possible to bypass the login form by editing the path of the cookie "sid" generated by the page. The attacker will have access to the router control panel with administrator privileges.
How severe is CVE-2018-17777?
CVE-2018-17777 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 1.87% probability of exploitation in the next 30 days.
How do I fix CVE-2018-17777?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-17777?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST