CVE-2020-8863 is an authentication bypass vulnerability in D-Link DIR-867, DIR-878, and DIR-882 routers running firmware 1.10B04, allowing network-adjacent attackers to gain unauthorized access. This flaw stems from improper authentication algorithm implementation within HNAP login requests. With a CVSS score of 8.8 (High), it presents a significant risk as it requires no authentication or user interaction, enabling attackers to escalate privileges and execute code. While there is no known active exploitation or public exploit code, the vulnerability has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.20b03CPE matchmatch criteria | cpe:2.3:o:dlink:dir-878_firmware:*:*:*:*:*:*:*:* | ||
<= 1.10b04CPE matchmatch criteria | cpe:2.3:o:dlink:dir-882_firmware:*:*:*:*:*:*:*:* | ||
<= 1.10b04CPE matchmatch criteria | cpe:2.3:o:dlink:dir-867_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.