CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with the password admin and root with the password 1234. | 9.8 |
Critical |
||
An issue was discovered on the D-Link DWR-932B router. HELODBG on port 39889 (UDP) launches the "/sbin/telnetd -l /bin/sh" command. | 9.8 |
Critical |
||
An issue was discovered on the D-Link DWR-932B router. There is a hardcoded WPS PIN of 28296607. | 7.5 |
High |
||
An issue was discovered on the D-Link DWR-932B router. WPS PIN generation is based on srand(time(0)) seeding. | 7.5 |
High |
||
An issue was discovered on the D-Link DWR-932B router. qmiweb provides sensitive information for CfgType=get_homeCfg requests. | 7.5 |
High |
||
An issue was discovered on the D-Link DWR-932B router. qmiweb allows command injection with ` characters. | 9.8 |
Critical |
||
An issue was discovered on the D-Link DWR-932B router. qmiweb allows directory listing with ../ traversal. | 7.5 |
High |
||
An issue was discovered on the D-Link DWR-932B router. qmiweb allows file reading with ..%2f traversal. | 7.5 |
High |
||
An issue was discovered on the D-Link DWR-932B router. A secure_mode=no line exists in /var/miniupnpd.conf. | 7.5 |
High |
||
An issue was discovered on the D-Link DWR-932B router. /var/miniupnpd.conf has no deny rules. | 7.5 |
High |