vendor:
DSL-2740B
by:
Ivano Binetti
5.5
CVSS
MEDIUM
CSRF
352
CWE
Product Name: DSL-2740B
Affected Version From: DSL-2740B
Affected Version To: DSL-2740B
Patch Exists: NO
Related CWE: CVE-2013-5730
CPE: h:d-link:dsl-2740b
Platforms Tested:
2013
D-Link DSL-2740B (ADSL Router) CSRF Vulnerability
The D-Link DSL-2640B's web interface is prone to CSRF vulnerabilities which allows to change router parameters and perform modifications to the router's parameters. The specific changes described in the advisory are disabling/enabling Wireless MAC Address Filter, disabling/enabling all the Firewall protections, and enabling/disabling Remote Management.
Mitigation:
Implement proper CSRF protection mechanisms in the router's web interface.