Security Advisory

CVE-2017-14422

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-09-13 17:00:00
Last updated 2024-08-05 19:27:40
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices use the same hardcoded /etc/stunnel.key private key across different customers' installations, which allows remote attackers to defeat the HTTPS cryptographic protection mechanisms by leveraging knowledge of this key from another installation.