#VU49089 Information disclosure in DSL-2888A - CVE-2020-24577
Published: December 18, 2020
DSL-2888A
D-Link
Description
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application at the following URLs:
http://DeviceIP/tmp/home/wan_stat
http://DeviceIP/tmp/var/passwd
A remote authenticated user can obtain internet connection credentials and password hash of the admin account by inspecting the application's response body.