CVE-2020-13787
Description
D-Link DIR-865L Ax 1.20B01 Beta devices have Cleartext Transmission of Sensitive Information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
D-Link DIR-865L Ax routers running firmware 1.20B01 Beta transmit sensitive data in cleartext, enabling network sniffing attacks.
Vulnerability
The D-Link DIR-865L Ax router with firmware version 1.20B01 Beta (released August 9, 2018) transmits sensitive information in cleartext over the network [1][2]. This vulnerability affects the administrative web interface and other services that handle credentials or session tokens without encryption.
Exploitation
An attacker with network access to the router's traffic (e.g., on the same local network or via a compromised upstream link) can passively sniff unencrypted communications. No authentication is required to capture the cleartext data. The attacker can use packet capture tools to intercept HTTP requests and responses containing sensitive information such as session cookies or administrative credentials.
Impact
Successful exploitation allows the attacker to obtain sensitive information, including session cookies and possibly administrative credentials. With these, the attacker can hijack an active administrative session, gaining unauthorized access to the router's management interface. This can lead to further compromise, such as file manipulation or command execution, as noted in the Unit42 report [1].
Mitigation
D-Link has released a beta patch (1.20B01 Beta) but the DIR-865L reached End of Support/End of Life on February 1, 2016 [2]. No further firmware updates are planned. Users are strongly recommended to replace the device with a supported model. As a workaround, avoid using the router for sensitive transactions and ensure it is isolated from untrusted networks.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- D-Link/DIR-865Ldescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- supportannouncement.us.dlink.com/announcement/publication.aspxmitrex_refsource_MISC
- unit42.paloaltonetworks.com/6-new-d-link-vulnerabilities-found-on-home-routers/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.