VendorsD-Linkdsl-2875al_firmwareany version
Vulnerabilities

D-Link DSL-2875AL Firmware any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2019-15655
D-Link DSL-2875AL devices through 1.00.05 are prone to password disclosure via a simple crafted /romfile.cfg request to the web management server. This request doesn't require any authentication and will lead to saving the configuration file. The password is stored in cleartext.
Published 2020-03-19 · Modified
7.5EPSS 0.014
CVE-2019-15656
D-Link DSL-2875AL and DSL-2877AL devices through 1.00.05 are prone to information disclosure via a simple crafted request to index.asp on the web management server because of username_v and password_v variables.
Published 2020-03-19 · Modified
7.5EPSS 0.013