CVE-2015-7247: D-Link Dvg-n5402sp Firmware

Critical severity, CVSS 9.8. EPSS: 10.2% chance of exploitation in the next 30 days.

D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and web account hashes (super and admin) in plaintext when running a configuration backup, which allows remote attackers to obtain sensitive information.

Affected products

  • D-Link Dvg-n5402sp Firmware: version w1000cn-00 only; version w1000cn-03 only; version w2000en-00 only

Published 2017-04-24. Last modified 2026-06-17.