Authentication Bypass in D-Link D-View 8
77Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 9.8epss 68%
from disclosure to weapon
Published on NVDSep 20
VulnCheck+75d
exploitation probability
68%top 1% of all CVEs
observed exploitation
yesVulnCheck
Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
D-Link · D-View 8