HIGH🇵🇱 Wersja polska

CVE-2019-13264

CVSS 8.8v3.1pub. 2019-08-27upd. 2024-11-21

D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. In order to transfer data from the host network to the guest network, the sender joins and then leaves an IGMP group. After it leaves, the router (following the IGMP protocol) creates an IGMP Membership Query packet with the Group IP and sends it to both the Host and the Guest networks. The data is transferred within the Group IP field, which is completely controlled by the sender.

CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Dlink Dir 825\/ac G1

    HW
    Dlink
    all versions
  • Dlink Dir 825\/ac G1 Firmware

    OS
    Dlink
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2019-13263HIGH8.8same product

D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network ...

CVE-2019-13265HIGH8.8same product

D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network ...

CVE-2024-3272CRITICAL9.8⚠ KEVPL ✓same vendor

D-Link DNS-320L/325/327L/340L — zakodowane na stałe poświadczenia (hard-coded credentials)

CVE-2023-25280CRITICAL9.8⚠ KEVPL ✓same vendor

Command Injection w D-Link DIR-820L umożliwiający eskalację uprawnień do root

CVE-2016-20017CRITICAL9.8⚠ KEVPL ✓same vendor

D-Link DSL-2750B — zdalne command injection bez uwierzytelnienia (CLI)