Required CVE Record Information
Description
An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilege account) access, an attacker can intercept the response from a POST request to obtain "Admin" rights due to the admin password being displayed in XML.
References 2 Total
- seclists.org: 20180827 CVE-2018-12710 mailing-list
- exploit-db.com: 45306 exploit
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 2 Total
- seclists.org: 20180827 CVE-2018-12710 mailing-listx_transferred
- exploit-db.com: 45306 exploitx_transferred