漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
D-Link Nuclias Connect <= v1.3.1.4 Forgot Password Account Enumeration
Vulnerability Description
D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The application's 'Forgot Password' endpoint returns distinct JSON responses depending on whether the supplied email address is associated with an existing account. Because the responses differ in the `data.exist` boolean value, an unauthenticated remote attacker can enumerate valid email addresses/accounts on the server. NOTE: D-Link states that a fix is under development.
CVSS Information
N/A
Vulnerability Type
响应差异性信息暴露
Vulnerability Title
D-Link Nuclias Connect 安全漏洞
Vulnerability Description
D-Link Nuclias Connect是中国友讯(D-Link)公司的一套无线网络集中管理系统。 D-Link Nuclias Connect 1.3.1.4及之前版本存在安全漏洞,该漏洞源于忘记密码端点存在可观察的响应差异,可能导致远程攻击者枚举有效电子邮件地址。
CVSS Information
N/A
Vulnerability Type
N/A