D-Link DWL-900AP+ Access Point 2.1 and 2.2 allows remote attackers to access the TFTP server without authentication and read the config.img file, which contains sensitive information such as the administrative password, the WEP encryption keys, and network configuration information.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/6015 | broken link third party advisory vdb entry |
http://www.iss.net/security_center/static/10424.php | vdb entry broken link |
http://online.securityfocus.com/archive/1/296374 | broken link mailing list third party advisory vdb entry |