VYPR
Unrated severityNVD Advisory· Published Oct 25, 2019· Updated Aug 6, 2024

CVE-2013-4855

CVE-2013-4855

Description

D-Link DIR-865L has SMB Symlink Traversal due to misconfiguration in the SMB service allowing symbolic links to be created to locations outside of the Samba share.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

D-Link DIR-865L SMB service misconfiguration allows symbolic link traversal, enabling local attackers to read or write files outside the Samba share.

Vulnerability

The D-Link DIR-865L router ships with an SMB (Samba) service that is misconfigured to allow symbolic links to be created that point to locations outside the designated Samba share [1]. This symlink traversal vulnerability permits a local attacker with access to the SMB share to escape the share boundary. The affected model is the D-Link DIR-865L; specific firmware versions are not disclosed in the available references.

Exploitation

An attacker must be on the local network and have credentials or the ability to mount the SMB share. Once connected, the attacker can create a symbolic link within the share that points to an arbitrary directory on the filesystem (e.g., /etc or /var). Accessing the symlink then allows reading or writing files outside the intended share. No authentication bypass is required beyond normal SMB access.

Impact

Successful exploitation allows a local attacker to read sensitive files (e.g., configuration, password hashes) and potentially write arbitrary files, which could lead to full compromise of the router's configuration or operating system. The attacker gains the ability to modify system files, enabling persistent backdoor or redirection of network traffic.

Mitigation

As of the publication date (October 2019), no firmware update has been identified in the available references that addresses this vulnerability [1]. Users are advised to disable the SMB service on the router if it is not required, or restrict SMB access to trusted IP addresses via firewall rules. Segmenting the router's management interface from the user network can also reduce exposure.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.