CRITICAL🇵🇱 Wersja polska

CVE-2024-38437

CVSS 9.8v3.1pub. 2024-07-21upd. 2024-11-21

D-Link - CWE-288:Authentication Bypass Using an Alternate Path or Channel

🤖 AI Analysis
How it works

The vulnerability classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel) and CWE-306 (Missing Authentication for Critical Function) allows an attacker to access protected device functions without providing correct authentication credentials. This is possible by exploiting an alternative path or communication channel that is not covered by standard identity verification. The attack can be conducted remotely over the network, without user interaction, and without requiring any privileges.

Impact

An attacker can gain unauthorized access to the device with full privileges, which may result in taking control of the router/modem, modifying its configuration, intercepting network traffic, or enabling further lateral movement within the network.

Mitigation & patch

Patches available from the manufacturer should be applied according to references. Additionally, it is recommended to restrict access to the device management interface only to trusted IP addresses and to isolate the device from unauthorized network segments until updates are deployed.

Who is affected

D-Link DSL-225 devices and their firmware — specific versions indicated in manufacturer references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Dlink Dsl 225

    HW
    Dlink
    all versions
  • Dlink Dsl 225 Firmware

    OS
    Dlink
    bz_1.00.16
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2024-38438CRITICAL9.8PL ✓same product

D-Link DSL-225: Authentication Bypass przez atak capture-replay

CVE-2024-3272CRITICAL9.8⚠ KEVPL ✓same vendor

D-Link DNS-320L/325/327L/340L — zakodowane na stałe poświadczenia (hard-coded credentials)

CVE-2023-25280CRITICAL9.8⚠ KEVPL ✓same vendor

Command Injection w D-Link DIR-820L umożliwiający eskalację uprawnień do root

CVE-2016-20017CRITICAL9.8⚠ KEVPL ✓same vendor

D-Link DSL-2750B — zdalne command injection bez uwierzytelnienia (CLI)

CVE-2022-37055CRITICAL9.8⚠ KEVPL ✓same vendor

Buffer overflow w D-Link Go-RT-AC750 via cgibin/hnap_main — RCE bez uwierzytelnienia