vendor:
DAP-1360
by:
r3m0t3nu11
CVSS
HIGH
File path traversal and Cross site scripting[reflected]
N/A
CWE
Product Name: DAP-1360
Affected Version From: Firmware version: 6.O5
Affected Version To: Firmware version: 6.O5
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: All Platforms
2018
D-Link DAP-1360 File path traversal and Cross site scripting[reflected] can lead to Authentication Bypass easily.
After Successfully Connected to D-Link DIR-600 Router(FirmWare Version : 2.01), Any User Can Bypass The Router's Root password as well bypass admin panel. D-Link DAP-1360 devices with v6.x firmware allow remote attackers to read passwords via a errorpage paramater which lead to absolute path traversal attack. Its More Dangerous when your Router has a public IP with remote login enabled.
Mitigation:
Disable remote login and use strong passwords for authentication.