vendor:
DIR-816L
by:
Bhadresh Patel
7,9
CVSS
(AV:A/AC:M/Au:N/C:C/I:C/A:C)
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: DIR-816L
Affected Version From: <=2.06.B01
Affected Version To: <=2.06.B01
Patch Exists: YES
Related CWE: CVE-2015-5999
CPE: h:d-link:dir-816l
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
D-link wireless router DIR-816L – Cross-Site Request Forgery (CSRF) vulnerability
An attacker who lures a DIR-816L authenticated user to browse a malicious website can exploit cross site request forgery (CSRF) to submit commands to DIR-816L wireless router and gain control of the product. The attacker could submit variety of commands including but not limited to changing the admin account password, changing the network policy, etc.
Mitigation:
Implementing a secure authentication mechanism and using a secure communication protocol like HTTPS can help mitigate the risk of CSRF attacks.