vendor:
Residential Gateway DI3124
by:
Todor Donev
8.8
CVSS
HIGH
Unauthenticated Remote DNS Change
284
CWE
Product Name: Residential Gateway DI3124
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2015
Broadlight Residential Gateway DI3124 Unauthenticated Remote DNS Change
Broadlight Residential Gateway DI3124 is vulnerable to unauthenticated remote DNS change. An attacker can exploit this vulnerability by sending a malicious GET request to the target server. The malicious request will change the DNS server of the target device to the attacker's DNS server. This will allow the attacker to intercept the traffic of the target device.
Mitigation:
Authentication should be enabled for the GET requests to the target server. Access to the target server should be restricted to trusted IP addresses.