Vulnerabilities > CVE-2019-17525 - Improper Restriction of Excessive Authentication Attempts vulnerability in Dlink Dir-615 Firmware 20.10

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
dlink
CWE-307
exploit available

Summary

The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks.

Vulnerable Configurations

Part Description Count
OS
Dlink
1
Hardware
Dlink
1

Exploit-Db

idEDB-ID:48551
last seen2020-06-04
modified2020-06-04
published2020-06-04
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/48551
titleD-Link DIR-615 T1 20.10 - CAPTCHA Bypass

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/157936/dlinkdir615-captchabypass.txt
idPACKETSTORM:157936
last seen2020-06-05
published2020-06-04
reporterHuzaifa Hussain
sourcehttps://packetstormsecurity.com/files/157936/D-Link-DIR-615-T1-20.10-CAPTCHA-Bypass.html
titleD-Link DIR-615 T1 20.10 CAPTCHA Bypass