vendor:
DIR-100
by:
Felix Richter
9,8
CVSS
CRITICAL
Authentication Bypass, Information Disclosure, Cross-Site Scripting, Cross-Site Request Forgery
287, 255, 352, 79, 200
CWE
Product Name: DIR-100
Affected Version From: 4.03B07 (from 2012-04-10)
Affected Version To: 4.03B13 (from 2013-10-11)
Patch Exists: YES
Related CWE: CVE-2013-7051, CVE-2013-7052, CVE-2013-7053, CVE-2013-7054, CVE-2013-7055
CPE: h:d-link:dir-100
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2013
Router D-Link DIR-100 Multiple Vulnerabilities
The D-Link DIR-100 is vulnerable to multiple issues. By sending a specially crafted HTTP request to the device, an attacker can retrieve the administrator password without authentication, retrieve sensitive configuration parameters like the pppoe username and password without authentication, execute arbitrary commands on the device, and perform CSRF attacks.
Mitigation:
Upgrade to the latest version of the firmware.