S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2019-17506 Scanner

CVE-2019-17506 scanner - Improper Access Control vulnerability in D-Link DIR-868L and DIR-817LW

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.2k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-17506
9.8
CVSS

There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the router's username and password (and other information) via a DEVICE.ACCOUNT value for SERVICES in conjunction with AUTHORIZED_GROUP=1%0a to getcfg.php. This could be used to control the router remotely.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers are popular network devices used by individuals and businesses alike. These routers act as a gateway between a local network and the internet, providing wireless connectivity to laptops, smartphones, and other devices.

Recently, a significant vulnerability was detected in these routers that could potentially put the security of the entire network at risk. The vulnerability code, CVE-2019-17506, allows an attacker to gain access to the router's username and password, as well as other sensitive information, by using a DEVICE.ACCOUNT value for SERVICES in conjunction with AUTHORIZED_GROUP=1%0a to getcfg.php. This means that an attacker can remotely control the router without any authentication requirements.

Exploiting this vulnerability can lead to a variety of issues, including data theft, unauthorized access to network resources, and disruption of network services. Attackers could also use the router as a pivot point to launch attacks against other devices on the network.

At s4e.io, our platform provides advanced security features that allow users to quickly identify and address vulnerabilities in their digital assets. By subscribing to our service, users can stay ahead of the latest threats and keep their systems secure. Don't wait until it's too late – sign up today and protect your digital assets!

 

REFERENCES

Solution Advice

To protect against this vulnerability, users of these routers should take the following precautions:

  • Update to the latest firmware version available
  • Disable any unused services and ports on the router
  • Change the default username and password for the router's administration interface
  • Enable encryption for wireless network connections
  • Use a firewall to monitor and block suspicious traffic

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-17506 scanner - Improper Access Control vulnerability in D-Link DIR-868L and DIR-817LW | S4E