vendor:
DIR-600M
by:
Ajay S. Kulal
8.8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: DIR-600M
Affected Version From: Hardware version: C1, Firmware version: 3.03
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2017-5874
CPE: h:dlink:dir-600m
Platforms Tested: All Platforms
2017
D-link wireless router DIR-600M – Cross-Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in the DIR-600M wireless router enables an attacker to perform an unwanted action on a wireless router for which the user/admin is currently authenticated. An attacker who lures a DIR-600M authenticated user to browse a malicious website can exploit cross site request forgery (CSRF) to add new admin, change wifi password and to change other network settings.