vendor:
DIR-600L
by:
Dhruv Shah
N/A
CVSS
N/A
Cross Site Request Forgery
Unknown
CWE
Product Name: DIR-600L
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: Unknown
Platforms Tested: Router Web Server
2014
Dlink DIR-600L Hardware Version AX Firmware Version 1.00 CSRF Vulnerability
This Modem's Web Application suffers from Cross-site request forgery through which attacker can manipulate user data via sending him malicious craft url. The Modems's Application not using any security token to prevent it against CSRF. You can manipulate any userdata. PoC and Exploit to change user password:
Mitigation:
Unknown