CRITICAL🇵🇱 Wersja polska

CVE-2024-38438

CVSS 9.8v3.1pub. 2024-07-21upd. 2024-11-21

D-Link - CWE-294: Authentication Bypass by Capture-replay

🤖 AI Analysis
How it works

The authentication mechanism in the device is vulnerable to a capture-replay attack (CWE-294), which involves intercepting valid authentication credentials transmitted over the network and then replaying them to gain access. The device does not implement appropriate protection mechanisms against reuse of intercepted sessions or authentication tokens. A remote attacker, without any privileges and without user interaction, can effectively impersonate an authenticated user.

Impact

An attacker can gain unauthorized access to the device's administrative panel, leading to complete control over the DSL router — including changes to network configuration, interception of network traffic, and potential compromise of system confidentiality, integrity, and availability.

Mitigation & patch

Security patches available from the manufacturer should be applied in accordance with the references. It is also recommended to restrict access to the device management interface exclusively to trusted IP addresses and to avoid exposing the administrative panel directly to the public Internet.

Who is affected

D-Link DSL-225 and D-Link DSL-225 Firmware — specific versions indicated in the manufacturer's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Dlink Dsl 225

    HW
    Dlink
    all versions
  • Dlink Dsl 225 Firmware

    OS
    Dlink
    gem_1.00.02
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2024-38437CRITICAL9.8PL ✓same product

Pominięcie uwierzytelniania w D-Link DSL-225 (Auth Bypass)

CVE-2024-3272CRITICAL9.8⚠ KEVPL ✓same vendor

D-Link DNS-320L/325/327L/340L — zakodowane na stałe poświadczenia (hard-coded credentials)

CVE-2023-25280CRITICAL9.8⚠ KEVPL ✓same vendor

Command Injection w D-Link DIR-820L umożliwiający eskalację uprawnień do root

CVE-2016-20017CRITICAL9.8⚠ KEVPL ✓same vendor

D-Link DSL-2750B — zdalne command injection bez uwierzytelnienia (CLI)

CVE-2022-37055CRITICAL9.8⚠ KEVPL ✓same vendor

Buffer overflow w D-Link Go-RT-AC750 via cgibin/hnap_main — RCE bez uwierzytelnienia