vendor:
DSL-526B ADSL2+ AU_2.01
by:
Todor Donev
7.8
CVSS
HIGH
Unauthenticated Remote DNS Change
284
CWE
Product Name: DSL-526B ADSL2+ AU_2.01
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: h:d-link:dsl-526b_adsl2+_au_2.01
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2015
D-Link DSL-526B ADSL2+ AU_2.01 Unauthenticated Remote DNS Change
This vulnerability allows an unauthenticated attacker to remotely change the DNS settings of the D-Link DSL-526B ADSL2+ AU_2.01 router. By sending a specially crafted HTTP GET request to the dnscfg.cgi script, an attacker can change the DNS settings of the router. This can be used to redirect users to malicious websites or to intercept traffic.
Mitigation:
Users should ensure that their router is running the latest firmware version and that the default credentials are changed.