Re: [FD] [CVE-2018-18009] dirary0.js on D-Link DIR-140L, DIR-640L devices allows remote unauthenticated attackers to discover admin credentials

2019-01-01 Thread Tyler Cui
Correction of the typo: "An authenticated user can visit the file dirary0.js" should be "An unauthenticated user can visit the file dirary0.js" ________ From: Tyler Cui Sent: Monday, 17 December 2018 12:11 AM To: fulldisclosure@seclists.org Subj

Re: [FD] [CVE-2018-18008] spaces.htm on multiple D-Link devices (DSL, DIR, DWR) allows remote unauthenticated attackers to discover admin credentials

2019-01-01 Thread Tyler Cui
Correction of the typo: "An authenticated user can visit the page spaces.htm" should be "An unauthenticated user can visit the page spaces.htm" From: Fulldisclosure on behalf of Tyler Cui Sent: Monday, 17 December 2018 12:10 AM To: fulldis

Re: [FD] [CVE-2018-18007] atbox.htm on D-Link DSL-2770L devices allows remote unauthenticated attackers to discover admin credentials

2019-01-01 Thread Tyler Cui
Correction of the typo: "An authenticated user can visit the page atbox.htm" should be "An unauthenticated user can visit the page atbox.htm" ________ From: Tyler Cui Sent: Monday, 17 December 2018 12:09 AM To: fulldisclosure@seclists.org Subj

[FD] [CVE-2018-18009] dirary0.js on D-Link DIR-140L, DIR-640L devices allows remote unauthenticated attackers to discover admin credentials

2018-12-21 Thread Tyler Cui
[Vendor] us.dlink.com [Product] DIR-140L (version 1.02) DIR-640L (version 1.01RU) Other versions might also be affected. [Vulnerability Type] admin credentials disclosure [Affected Component] Web Interface [CVE Reference] CVE-2018-18009 [Security Issue] An authenticated user can visit the

[FD] [CVE-2018-18008] spaces.htm on multiple D-Link devices (DSL, DIR, DWR) allows remote unauthenticated attackers to discover admin credentials

2018-12-21 Thread Tyler Cui
[Vendor] us.dlink.com [Product] D-Link DSL-2770L (version ME_1.01, ME_1.02, AU_1.06) D-Link DIR-140L, DIR-640L (version 1.00, 1.01RU, 1.02) D-Link DWR-116, DWR-512, DWR-555, DWR-921 (version V1.03, V1.05, V2.01, V2.02) [Vulnerability Type] admin credentials disclosure [Affected Component] Web

[FD] [CVE-2018-18007] atbox.htm on D-Link DSL-2770L devices allows remote unauthenticated attackers to discover admin credentials

2018-12-21 Thread Tyler Cui
[Vendor] us.dlink.com [Product] D-Link DSL-2770L (version ME_1.01, ME_1.02, AU_1.06) [Vulnerability Type] admin credentials disclosure [Affected Component] Web Interface [CVE Reference] CVE-2018-18007 [Security Issue] An authenticated user can visit the page atbox.htm, for example, http: