peter bassill · operator
$ cve CVE-2017-8415 JSON

CVE-2017-8415

9.8
CRITICAL · CVSS 3.1 · EPSS 3.9% (pctl 90)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device has a custom telnet daemon as a part of the busybox and retrieves the password from the shadow file using the function getspnam at address 0x00053894. Then performs a crypt operation on the password retrieved from the user at address 0x000538E0 and performs a strcmp at address 0x00053908 to check if the password is correct or incorrect. However, the /etc/shadow file is a part of CRAM-FS filesystem which means that the user cannot change the password and hence a hardcoded hash in /etc/shadow is used to match the credentials provided by the user. This is a salted hash of the string "admin" and hence it acts as a password to the device which cannot be changed as the whole filesystem is read only.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.93% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-798
On CISA KEVno
Public exploitnone known
Published2019-07-02
Last modified2026-06-17

Affected (4)

VendorProduct
dlinkdcs-1100
dlinkdcs-1100 firmware
dlinkdcs-1130
dlinkdcs-1130 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD