vendor:
DCS-936L
by:
SlidingWindow
8,8
CVSS
HIGH
CSRF
352
CWE
Product Name: DCS-936L
Affected Version From: 1.02.01
Affected Version To: 1.02.01
Patch Exists: Yes
Related CWE: CVE-2017-7851
CPE: h:d-link:dcs-936l
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2017
D-Link DCS-936L network camera incomplete/weak CSRF protection vulnerability
D-Link DCS-936L devices with firmware 1.02.01 have CSRF. If a victim is logged into the camera's web console and visits a malicious site hosting a <Target_Device_IP.HTML> from another tab in the same browser, the malicious site can send requests to the victim's device. An attacker can add a new user, replace the firmware image with a malicious one, or connect the victim's device to a rogue Wireless Network. An attacker can easily find out public IP address of victim's device on Shodan or similar search engines to create <Target_Device_IP.HTML> file. Victim must be logged into the camera's web console and visit attacker's site from another tab in the same browser.
Mitigation:
Update to the latest version of the firmware, or disable the web console.