Information disclosure in DIR-823G - CVE-2019-7388
Published: February 6, 2019
DIR-823G
Detailed vulnerability description
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The vulnerability exists in /bin/goahead due to incorrect access control. A remote unauthenticated attacker can get sensitive information (such as MAC address) about all clients in the WLAN via the GetClientInfo HNAP API without authentication.