CRITICAL🇵🇱 Wersja polska

CVE-2023-51987

CVSS 9.8v3.1pub. 2024-01-11upd. 2025-06-20

D-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows attackers to log in to administrator accounts with empty passwords.

🤖 AI Analysis
How it works

The HNAP1 interface (Home Network Administration Protocol) in the router firmware does not properly verify credentials during the login process. The vulnerability classified as CWE-306 (missing authentication for critical function) allows authentication with an empty password. An attacker remotely, without any privileges and without user interaction, can gain access to the administrator account.

Impact

An attacker gains full administrative access to the device, enabling takeover of the router, modification of network configuration, interception of network traffic, and potential use of the device as an entry point to the local network.

Mitigation & patch

Apply patches available from the manufacturer according to the references. If an update is not available, consider disabling access to the HNAP1 interface from the WAN side and restricting access to the administration panel only to trusted hosts on the local network.

Who is affected

D-Link DIR-822+ in firmware version V1.0.2

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Dlink Dir 822

    HW
    Dlink
    all versions
  • Dlink Dir 822 Firmware

    OS
    Dlink
    1.0.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2019-17621CRITICAL9.8⚠ KEVPL ✓same product

D-Link DIR-859: RCE jako root przez UPnP bez uwierzytelnienia

CVE-2023-51984CRITICAL9.8PL ✓same product

Command injection w D-Link DIR-822+ — zdalne wykonanie poleceń

CVE-2019-6258CRITICAL9.8PL ✓same product

Buffer overflow w D-Link DIR-822 przez protokół HNAP (SetClientInfo)

CVE-2018-19986CRITICAL9.8PL ✓same product

Command injection w D-Link DIR-818LW i DIR-822 przez parametr RemotePort

CVE-2018-19989CRITICAL9.8PL ✓same product

Command injection w D-Link DIR-822 przez parametr uplink (HNAP1)