vendor:
DSL-2750U
by:
khaledmohdar
8,8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: DSL-2750U
Affected Version From: ME_1.09
Affected Version To: ME_1.09
Patch Exists: N/A
Related CWE: N/A
CPE: h:d-link:dsl-2750u
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 32-bit
N/A
{D-Link DSL-2750U} CSRF Vulnerability
This router allows an attacker to bypass authentication and login to the setup page after that just make any settings and save or apply it and it's going to say 'wrong old password'. Don't worry just hit ok. Now the attacker is in the Router settings and can download the config file or whatever they want. The attacker can then easily make a new settings including a new login password.
Mitigation:
Implementing a strong authentication mechanism and using anti-CSRF tokens can help mitigate CSRF attacks.