vendor:
DSL-2730U Wireless N 150
by:
B GOVIND
8.8
CVSS
HIGH
Cross Site Request Forgery
352
CWE
Product Name: DSL-2730U Wireless N 150
Affected Version From: Hardware ver C1, Firmware ver: IN_1.0.0
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2017-6411
CPE: dsl-2730u
Platforms Tested:
2017
DLink DSL-2730U Wireless N 150, Change DNS Configuration bypassing ‘admin’ privilege
Cross Site Request Forgery can be used to manipulate dnscfg.cgi in this device. An insider / external attacker (remote management to be enabled for external attacker) can change primary and secondary DNS IP address to some malicious IP address without using ‘admin’ account.
Mitigation:
Unknown