{
    "id": "CVE-2017-8415",
    "published": "2019-07-02 21:15:10",
    "last_modified": "2026-06-17 01:26:21",
    "cvss_score": "9.8",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-798",
    "description": "An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device has a custom telnet daemon as a part of the busybox and retrieves the password from the shadow file using the function getspnam at address 0x00053894. Then performs a crypt operation on the password retrieved from the user at address 0x000538E0 and performs a strcmp at address 0x00053908 to check if the password is correct or incorrect. However, the /etc/shadow file is a part of CRAM-FS filesystem which means that the user cannot change the password and hence a hardcoded hash in /etc/shadow is used to match the credentials provided by the user. This is a salted hash of the string \"admin\" and hence it acts as a password to the device which cannot be changed as the whole filesystem is read only.",
    "epss_score": "0.03930",
    "epss_percentile": "0.90090",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-10-08 18:17:18",
    "priority": {
        "rank": 3,
        "label": "In your normal cycle",
        "why": "Critical by CVSS (9.8), but no sign of active exploitation."
    },
    "products": [
        {
            "vendor": "dlink",
            "product": "dcs-1100"
        },
        {
            "vendor": "dlink",
            "product": "dcs-1100_firmware"
        },
        {
            "vendor": "dlink",
            "product": "dcs-1130"
        },
        {
            "vendor": "dlink",
            "product": "dcs-1130_firmware"
        }
    ],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "http://packetstormsecurity.com/files/153226/Dlink-DCS-1130-Command-Injection-CSRF-Stack-Overflow.html",
        "https://github.com/ethanhunnt/IoT_vulnerabilities/blob/master/Dlink_DCS_1130_security.pdf",
        "https://seclists.org/bugtraq/2019/Jun/8",
        "http://packetstormsecurity.com/files/153226/Dlink-DCS-1130-Command-Injection-CSRF-Stack-Overflow.html",
        "https://github.com/ethanhunnt/IoT_vulnerabilities/blob/master/Dlink_DCS_1130_security.pdf",
        "https://seclists.org/bugtraq/2019/Jun/8"
    ]
}