vendor:
DIR-300, DIR-320, DIR-615 revD
by:
Craig Heffner
7,5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: DIR-300, DIR-320, DIR-615 revD
Affected Version From: All
Affected Version To: All
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: DIR-300, DIR-320, DIR-615 revD
2011
Multiple D-Link Router Authentication Bypass Vulnerabilities
Multiple D-Link routers that use a PHP based Web interface suffer from the same authentication bypass vulnerability which allows unprivileged users to view and modify administrative router settings. Further, even if remote administration is disabled this vulnerability can be exploited by a remote attacker via a CSRF attack.
Mitigation:
Disable remote administration, use strong passwords, and ensure that all routers are running the latest firmware version.