Vulnerability Details CVE-2017-14418
The D-Link NPAPI extension, as used in conjunction with D-Link DIR-850L REV. B (with firmware through FW208WWb02) devices, sends the cleartext admin password over the Internet as part of interaction with mydlink Cloud Services.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 67.4%
CVSS Severity
CVSS v3 Score 8.1
CVSS v2 Score 4.3
Products affected by CVE-2017-14418
-
cpe:2.3:h:dlink:dir-850l:-
-
cpe:2.3:o:dlink:dir-850l_firmware:-
-
cpe:2.3:o:dlink:dir-850l_firmware:1.02
-
cpe:2.3:o:dlink:dir-850l_firmware:1.08b03
-
cpe:2.3:o:dlink:dir-850l_firmware:1.08trb03
-
cpe:2.3:o:dlink:dir-850l_firmware:1.09
-
cpe:2.3:o:dlink:dir-850l_firmware:1.14b07
-
cpe:2.3:o:dlink:dir-850l_firmware:1.21b07
-
cpe:2.3:o:dlink:dir-850l_firmware:2.06
-
cpe:2.3:o:dlink:dir-850l_firmware:2.07.b05
-
cpe:2.3:o:dlink:dir-850l_firmware:2.21b01
-
cpe:2.3:o:dlink:dir-850l_firmware:2.22b02
-
cpe:2.3:o:dlink:dir-850l_firmware:fw114wwb07_h2ab
-
cpe:2.3:o:dlink:dir-850l_firmware:fw208wwb02