CVE-2017-14423: D-Link Dir-850l Firmware
High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.
htdocs/parentalcontrols/bind.php on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices does not prevent unauthenticated nonce-guessing attacks, which makes it easier for remote attackers to change the DNS configuration via a series of requests.
Affected products
- D-Link Dir-850l Firmware: before fw114wwb07_h2ab (fixed in fw114wwb07_h2ab); version fw114wwb07_h2ab only
Published 2017-09-13. Last modified 2026-06-17.