vendor:
DSL-2750B
by:
killall-9@mail.com
4,3
CVSS
MEDIUM
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: DSL-2750B
Affected Version From: Firmware Version: EU_2.02
Affected Version To: Hardware Version: B1
Patch Exists: N/A
Related CWE: N/A
CPE: h:d-link:dsl-2750b
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2014
D-Link DSL-2750B (ADSL Router) CSRF Vulnerability
The D-Link DSL-2750B's web interface (listening on tcp/ip port 80) is prone to CSRF vulnerabilities which allows to change router parameters. The proof-of-concept code includes an HTML page with an image tag that points to the vulnerable router's IP address.
Mitigation:
Implementing a CSRF token in the web application can help mitigate this vulnerability.