CVE-2017-14426 describes a critical vulnerability in D-Link DIR-850L REV. A and REV. B routers, where insecure file permissions (0644) are set for the /var/etc/shadow file, a symlink to /etc/shadow. This allows an authenticated local attacker to read, modify, or delete the shadow file, leading to a complete compromise of the device. With a CVSS score of 7.8 (High), this flaw grants an attacker full confidentiality, integrity, and availability impact. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< fw114wwb07_h2abCPE matchmatch criteria | cpe:2.3:o:dlink:dir-850l_firmware:*:*:*:*:*:*:*:* | ||
fw114wwb07_h2abCPE matchmatch criteria | cpe:2.3:o:dlink:dir-850l_firmware:fw114wwb07_h2ab:beta1:*:*:*:*:*:* | ||
<= fw208wwb02CPE matchmatch criteria | cpe:2.3:o:dlink:dir-850l_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.