← Back to CVE List
Vulnerability Intelligence Report

CVE-2014-7857

D-Link DNS-320L firmware before 1.04b12, DNS-327L before 1.03b04 Build0119, DNR-326 1.40b03, DNS-320B 1.02b01, DNS-345 1.03b06, DNS-325 1.05b03, and DNS-322L 2.00b07 allow remote attackers to bypass authentication and log in with administrator permissions by passing the cgi_set_wto command in the cmd parameter, and setting the spawned session's cookie to username=admin.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:15.17%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
d-link dns-322l_firmware all
dlink dns-322l all
d-link dns-325_firmware all
dlink dns-325 all
d-link dns-345_firmware all
dlink dns-345 all
d-link dns-320b_firmware all
dlink dns-320b all
d-link dnr-326_firmware all
dlink dnr-326 all
d-link dns-327l_firmware all
dlink dns-327l all
d-link dns-320l_firmware all
dlink dns-320l all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
15.165%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2014-10-03T00:00:00
Published2017-08-25T18:00:00
Patch Date2015-05-28
Last Updated2024-08-06T13:03:27

LINK COPIED TO CLIPBOARD