D-Link DWL-900AP+ Access Point 2.1 and 2.2 allows remote attackers to access the TFTP server without authentication and read the config.img file, which contains sensitive information such as the administrative password, the WEP encryption keys, and network configuration information.
References
Link | Resource |
---|---|
http://online.securityfocus.com/archive/1/296374 | Broken Link Third Party Advisory VDB Entry |
http://www.iss.net/security_center/static/10424.php | Broken Link |
http://www.securityfocus.com/bid/6015 | Broken Link Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2002-12-31 05:00
Updated : 2024-02-14 17:25
NVD link : CVE-2002-1810
Mitre link : CVE-2002-1810
CVE.ORG link : CVE-2002-1810
JSON object : View
Products Affected
dlink
- dwl-900ap\+_firmware
- dwl-900ap\+
CWE
CWE-306
Missing Authentication for Critical Function