vendor:
DWR-116 / DWR-116A1
by:
Patryk Bogdan
7,5
CVSS
HIGH
Unauthorized File Download
22
CWE
Product Name: DWR-116 / DWR-116A1
Affected Version From: V1.01(EU), V1.00(CP)b10
Affected Version To: V1.05(AU)
Patch Exists: YES
Related CWE: CVE-2017-6190
CPE: h:d-link:dwr-116
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: V1.01(EU), V1.00(CP)b10, V1.05(AU)
2016
D-Link DWR-116 Arbitrary File Download
D-Link DWR-116 with firmware before V1.05b09 suffers from vulnerability which leads to unathorized file download from device filesystem.
Mitigation:
Update device to the new firmware (V1.05b09)