Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query history.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
http://d-link.com | broken link |
https://www.dlink.com/en/security-bulletin/ | not applicable |
http://dir-868lw.com | url repurposed broken link |
https://github.com/jayus0821/uai-poc/blob/main/D-Link/DIR-868L/webaccess_UAI.md | third party advisory exploit |