vendor:
DSL-2730B AU
by:
Todor Donev
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: DSL-2730B AU
Affected Version From: 02.01
Affected Version To: 02.01
Patch Exists: NO
Related CWE: N/A
CPE: h:d-link:dsl-2730b_au
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
D-Link DSL-2730B AU_2.01 Authentication Bypass DNS Change
This security hole allows an attacker to bypass authentication and change the DNS. When the administrator is logged in the web management interface, an attacker may be able to completely bypass authentication phase and connect to the web management interface with administrator's credentials. This attack can also be performed by an external attacker who connects to the router's public IP address, if remote management is enabled. To change the DNS without logging into web management interface use the following URL: http://TARGET/dnscfg.cgi?dnsPrimary=8.8.8.8&dnsSecondary=8.8.4.4&dnsDynamic=0&dnsRefresh=1&dnsIfcsList=WAN-1
Mitigation:
Disable remote management and ensure that the router is not exposed to the public internet.