CVE-2020-29323

The D-link router DIR-885L-MFC 1.15b02, v1.21b05 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:dlink:dir-885l-mfc_firmware:1.15b02:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-885l-mfc_firmware:1.21b05:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-885l-mfc:-:*:*:*:*:*:*:*

History

12 Jul 2022, 17:42

Type Values Removed Values Added
CWE CWE-798

10 Jun 2021, 18:52

Type Values Removed Values Added
CPE cpe:2.3:o:dlink:dir-885l-mfc_firmware:1.15b02:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-885l-mfc:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-885l-mfc_firmware:1.21b05:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
CWE CWE-522
References (MISC) https://cybersecurityworks.com/zerodays/cve-2020-29323-telnet-hardcoded-credentials.html - (MISC) https://cybersecurityworks.com/zerodays/cve-2020-29323-telnet-hardcoded-credentials.html - Exploit, Third Party Advisory

04 Jun 2021, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-06-04 20:15

Updated : 2023-12-10 13:55


NVD link : CVE-2020-29323

Mitre link : CVE-2020-29323

CVE.ORG link : CVE-2020-29323


JSON object : View

Products Affected

dlink

  • dir-885l-mfc
  • dir-885l-mfc_firmware
CWE
CWE-522

Insufficiently Protected Credentials

CWE-798

Use of Hard-coded Credentials