vendor:
DSL-2750u and DSL-2730u wireless router
by:
SATHISH ARTHAR
7.5
CVSS
HIGH
Local File Inclusion
98
CWE
Product Name: DSL-2750u and DSL-2730u wireless router
Affected Version From: DSL-2750u (firmware: IN_1.08 )
Affected Version To: DSL-2730u (firmware: IN_1.02 )
Patch Exists: NO
Related CWE: N/A
CPE: h:dlink:dsl-2750u
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: linux
2015
Dlink Wireless Router Password File Access Exploit (Local File Inclusion)
The router suffers from an authenticated file inclusion vulnerability (LFI) when input passed thru the 'getpage' parameter to 'webproc' script is not properly verified before being used to include files. This can be exploited to include files from local resources.
Mitigation:
Input validation should be done to prevent the exploitation of this vulnerability.