PT-2014-2056 · D Link · D-Link Dir-600
Dawid Czagan
·
Publicado
2014-03-07
·
Atualizado
2024-12-20
·
CVE-2014-100005
CVSS v3.1
8.0
Alta
| Vetor | AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-600 router versions prior to 2.17b02
Description
The issue concerns a cross-site request forgery (CSRF) vulnerability. This vulnerability allows remote attackers to hijack the authentication of administrators for various requests, including creating an administrator account, enabling remote management via a crafted configuration module to "hedwig.cgi", activating new configuration settings via a SETCFG,SAVE,ACTIVATE action to "pigwidgeon.cgi", or sending a ping via a ping action to "diagnostic.php".
Recommendations
For D-Link DIR-600 router versions prior to 2.17b02, update the firmware to version 2.17b02 or later to resolve the issue.
As a temporary workaround, consider restricting access to the vulnerable API endpoints, such as "hedwig.cgi", "pigwidgeon.cgi", and "diagnostic.php", until a patch is available.
Avoid using the vulnerable configuration module and actions, such as SETCFG,SAVE,ACTIVATE and ping, in the affected API endpoints until the issue is resolved.
Exploit
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
D-Link Dir-600