D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnconfig.php.Referenceshttps://medium.com/%40s1kr10s/d-link-dir-859-unauthenticated-information-disclosure-en-faf1a9a13f3fhttps://medium.com/%40s1kr10s/d-link-dir-859-unauthenticated-information-disclosure-es-6540f7f55b03https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10147https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10146