PT-2014-2056 · D Link · D-Link Dir-600

Dawid Czagan

·

Publicado

2014-03-07

·

Atualizado

2024-12-20

·

CVE-2014-100005

CVSS v3.1

8.0

Alta

VetorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DIR-600 router versions prior to 2.17b02
Description The issue concerns a cross-site request forgery (CSRF) vulnerability. This vulnerability allows remote attackers to hijack the authentication of administrators for various requests, including creating an administrator account, enabling remote management via a crafted configuration module to "hedwig.cgi", activating new configuration settings via a SETCFG,SAVE,ACTIVATE action to "pigwidgeon.cgi", or sending a ping via a ping action to "diagnostic.php".
Recommendations For D-Link DIR-600 router versions prior to 2.17b02, update the firmware to version 2.17b02 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable API endpoints, such as "hedwig.cgi", "pigwidgeon.cgi", and "diagnostic.php", until a patch is available. Avoid using the vulnerable configuration module and actions, such as SETCFG,SAVE,ACTIVATE and ping, in the affected API endpoints until the issue is resolved.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-03952
CVE-2014-100005

Produtos afetados

D-Link Dir-600