VYPR
Unrated severityNVD Advisory· Published Jun 3, 2020· Updated Aug 4, 2024

CVE-2020-13785

CVE-2020-13785

Description

D-Link DIR-865L Ax 1.20B01 Beta devices have Inadequate Encryption Strength.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

D-Link DIR-865L Ax routers running firmware 1.20B01 Beta use weak encryption, enabling attackers to decrypt sensitive data.

Vulnerability

The D-Link DIR-865L router, hardware revision Ax, running firmware version 1.20B01 Beta (released August 9, 2018), suffers from inadequate encryption strength [1][2]. The vulnerability resides in the router's implementation of cryptographic protections, which fail to meet minimum security standards. The product reached its End of Support/End of Life on February 1, 2016, and the vulnerable firmware is a beta release provided after that date [2].

Exploitation

An attacker with adjacent network access to the router can exploit the weak encryption to sniff traffic and potentially decrypt sensitive information [1]. The exact attack vector is not detailed in available references, but inadequate encryption strength typically allows attackers to recover plaintext from captured encrypted communications without needing authentication or user interaction [1].

Impact

Successful exploitation leads to the disclosure of sensitive information transmitted to or from the router, including session cookies and other confidential data [1]. This information disclosure can be chained with other vulnerabilities (e.g., command injection CVE-2020-13782 or CSRF CVE-2020-13786) to gain administrative access or execute arbitrary commands [1].

Mitigation

D-Link has released a beta patch, but the DIR-865L hardware revision Ax reached its End of Support/End of Life on February 1, 2016; no further firmware updates are planned [2]. Users are strongly recommended to replace the device with a supported model [1][2]. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • D-Link/DIR-865Ldescription
  • Dlink/DIR-865Lllm-fuzzy
    Range: = 1.20B01 Beta

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.