D-Link DIR-852 Information Disclosure Vulnerability via Authentication Bypass

Vulnerability

An authentication bypass vulnerability has been identified in the D-Link DIR-852 router, specifically in versions through 1.00CN B09. This vulnerability resides in the 'phpcgi_main' function of the '/getcfg.php' file, part of the Device Configuration Handler component. The issue allows for unauthorized access to sensitive information by manipulating POST request parameters. Exploitation can be performed remotely, and a public exploit is available.

Impact

Exploitation of this vulnerability leads to unauthorized information disclosure, allowing attackers to access sensitive device configuration data, including administrator account credentials.

Reproduction

To reproduce this vulnerability, send a POST request to '/getcfg.php' with the 'SERVICES' parameter set to request specific device configuration files. Include a newline character to inject a forged 'AUTHORIZED_GROUP' value, bypassing the authentication check. The injected value will be processed first, allowing access to the requested information.

Remediation

It is recommended to implement restrictive firewall rules to block unauthorized access to the vulnerable device.

Added: Sep 8, 2025, 12:18 PM
Updated: Sep 8, 2025, 4:45 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
8.7
remediation
0.0
relevance
0.5
threat
6.4
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.