header-logo
Suggest Exploit
vendor:
DSL 3782
by:
Giulio Comi
9.8
CVSS
CRITICAL
Authentication Bypass
287
CWE
Product Name: DSL 3782
Affected Version From: A1_WI_20170303
Affected Version To: A1_WI_20170303
Patch Exists: YES
Related CWE: CVE-2018-8898
CPE: h:d-link:dsl-3782
Metasploit: N/A
Other Scripts: N/A
Platforms Tested: None
2018

D-Link DSL 3782 – Authentication Bypass

The web panel of D-Link DSL 3782 version (A1_WI_20170303) does not release a token ID (e.g. a session cookie) that identifies the logged in administrator, but only relies on a server-side timeout that lasts few minutes. In addition, a server-side mitigation in place prompts for login credentials everytime the webroot is loaded, but does leave the application endpoints unprotected and affected by this authentication bypass. Therefore, after a valid login of the administrator the web panel does not distinguish valid HTTP requests from the admin and the ones that come from other users. This way, an attacker can script an automatic routine that perform unwanted actions such as arbitrary modifications to router and SSIDs passwords and configurations.

Mitigation:

Implementing a secure authentication mechanism that requires a token ID (e.g. a session cookie) that identifies the logged in administrator.
Source

Exploit-DB raw data: