vendor:
DIR-615
by:
Sanyam Chawla
6.5
CVSS
MEDIUM
Privilege Escalation
264
CWE
Product Name: DIR-615
Affected Version From: 20.07
Affected Version To: 20.07
Patch Exists: YES
Related CWE: CVE-2019-19743
CPE: h:d-link:dir-615
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 and Kali Linux
2019
D-Link DIR-615 – Privilege Escalation
A vulnerability in D-Link DIR-615 Wi-Fi router allows an attacker to gain root privileges by changing the privileges id from 1 to 2 with Burp Suite. This can be done by logging in to the router gateway with normal user credentials and creating an account with a name and changing the privileges from user to root.
Mitigation:
Users should update their router firmware to the latest version to mitigate this vulnerability.