Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2018-12103

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

D-Link DIR-890L A2是友讯(D-Link)公司的一款无线路由器设备。 D-Link DIR-890L A2中存在安全漏洞。攻击者可利用该漏洞泄露访问接入点所使用的CAPTCHAs,并加载他们选择的CAPTCHA,从而未授权登录到访问接入点。

AI Predicted 7.5 Difficulty: Easy EPSS 0.45% · P37
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2018-12103

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
An issue was discovered on D-Link DIR-890L with firmware 1.21B02beta01 and earlier, DIR-885L/R with firmware 1.21B03beta01 and earlier, and DIR-895L/R with firmware 1.21B04beta04 and earlier devices (all hardware revisions). Due to the predictability of the /docs/captcha_(number).jpeg URI, being local to the network, but unauthenticated to the administrator's panel, an attacker can disclose the CAPTCHAs used by the access point and can elect to load the CAPTCHA of their choosing, leading to unauthorized login attempts to the access point.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
D-Link DIR-890L A2 访问控制错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
D-Link DIR-890L A2是友讯(D-Link)公司的一款无线路由器设备。 D-Link DIR-890L A2中存在安全漏洞。攻击者可利用该漏洞泄露访问接入点所使用的CAPTCHAs,并加载他们选择的CAPTCHA,从而未授权登录到访问接入点。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2018-12103

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2018-12103

登录查看更多情报信息。

Mailing List Discussions for CVE-2018-12103 (1)

Other References for CVE-2018-12103 (1)

Same Patch Batch · n/a · 2018-07-05 · 118 CVEs total

CVE-2018-13223 R Time Token v3 数字错误漏洞
CVE-2018-13300 FFmpeg 缓冲区错误漏洞
CVE-2018-13252 Entrust Datacard Syntera CS 跨站脚本漏洞
CVE-2018-13251 libming 安全漏洞
CVE-2018-13250 libming 安全漏洞
CVE-2018-13233 GSI 数字错误漏洞
CVE-2018-13232 ENTER 数字错误漏洞
CVE-2018-13231 ENTER 数字错误漏洞
CVE-2018-13230 DestiNeed 数字错误漏洞
CVE-2018-13229 RiptideCoin 数字错误漏洞
CVE-2018-13228 Crowdnext 数字错误漏洞
CVE-2018-13227 MoneyChainNet 数字错误漏洞
CVE-2018-13226 YLCToken 数字错误漏洞
CVE-2018-13225 MyYLC 数字错误漏洞
CVE-2018-13224 Virtual Energy Units 数字错误漏洞
CVE-2018-13212 EthereumLegit 数字错误漏洞
CVE-2018-13215 STK 数字错误漏洞
CVE-2018-13214 GMile 数字错误漏洞
CVE-2018-13213 TravelCoin 数字错误漏洞
CVE-2018-13210 Providence Crypto Casino 数字错误漏洞

Showing top 20 of 118 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2018-12103

No comments yet


Leave a comment