vendor:
DWR-932
by:
Saeed reza Zamanian
7,5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: DWR-932
Affected Version From: V4.00
Affected Version To: V4.00
Patch Exists: NO
Related CWE: N/A
CPE: h:d-link:dwr-932
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2016
D-Link DWR-932 Firmware <= V4.00 Authentication Bypass - Password Disclosure
The Cgi Script '/cgi-bin/dget.cgi' handles most of user side and server side requests, but there is no observation on requests recieved from unauthorized users. This allows an attacker to view the administrative or WiFi password in clear text by visiting certain URLs.
Mitigation:
Ensure that all requests are properly authenticated and authorized before being processed.