Incorrect Comparison in D-Link products - CVE-2020-8864
Published: February 25, 2020
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to a lack of proper handling of empty passwords within the handling of HNAP strncmp login requests. A remote attacker on the local network can bypass authentication and reset the admin password.
An attacker can leverage this vulnerability to execute arbitrary code on the router.
Affected software
DIR-878
DIR-882-US
How to mitigate CVE-2020-8864
DIR-878 - update to v1.30b10Beta
DIR-882-US - update to v1.30b10Beta