CVE-2013-7005 - CVE House
Back to Database
Status published Medium CVE-2013-7005

D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before...

Vulnerability Description

D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 stores account passwords in cleartext, which allows local users to obtain sensitive information by reading the Users[#]["Password"] fields in /tmp/teamf1.cfg.ascii.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-7005

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

dsr-150 firmware, dsr-150, dsr-250 firmware, dsr-250, dsr-1000n firmware, dsr-1000n, dsr-150n firmware, dsr-150n, dsr-500 firmware, dsr-500, dsr-1000 firmware, dsr-1000, dsr-250n firmware, dsr-500n firmware, dsr-500n
Vulnerable Versions:
0, 1.05b29, 1.05b35, 1.05b46, 1.05b50, 1.01b46, 1.01b56, 1.05b20, 1.05b53, 1.08b31, 1.01b50, 1.02b11, 1.02b25, 1.03b12, 1.03b23, 1.03b27, 1.03b36, 1.03b43, 1.04b58, 1.06b43, 1.06b53

Timeline

Official Publish: December 19th, 2013
Last Modified: August 6th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.