Vulnerability Details CVE-2019-15655
D-Link DSL-2875AL devices through 1.00.05 are prone to password disclosure via a simple crafted /romfile.cfg request to the web management server. This request doesn't require any authentication and will lead to saving the configuration file. The password is stored in cleartext.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.013
EPSS Ranking 79.0%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2019-15655
-
cpe:2.3:h:dlink:dsl-2875al:-
-
cpe:2.3:o:dlink:dsl-2875al_firmware:1.00.05