vendor:
DWR-113
by:
Blessen Thomas
8,8
CVSS
HIGH
Denial of Service via CSRF
352
CWE
Product Name: DWR-113
Affected Version From: v2.02 2013-03-13
Affected Version To: v2.02 2013-03-13
Patch Exists: YES
Related CWE: CVE-2014-3136
CPE: h:d-link:dwr-113
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
2014
Dlink DWR-113 Rev. Ax – CSRF causing Denial of Service
It was observed that the D-link DWR-113 wireless router is vulnerable to denial of service attack via CSRF(Cross-Site Request Forgery) vulnerability. An attacker could craft a malicious CSRF exploit to change the password in the password functionality when the user(admin) is logged in to the application ,as the user interface (admin panel) lacks the csrf token or nonce to prevent an attacker to change the password. As a result, as soon as the crafted malicious exploit is executed the router is rebooted and the user could not login thus forcing to reset the router’s device physically ,leading to a denial of service condition.
Mitigation:
Implementing CSRF tokens or nonce to prevent an attacker to change the password.