PT-2017-17708 · D Link · D-Link Dir-615

Pratik S. Shah

·

Publicado

2017-04-04

·

Atualizado

2023-04-26

·

CVE-2017-7398

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DIR-615 version 20.09
Description The issue allows an attacker to perform unwanted actions on a wireless router for which the user or admin is currently authenticated. This can be demonstrated by changing the Security option from WPA2 to None, or modifying the hiddenSSID parameter, SSID parameter, or a security-option password.
Recommendations For D-Link DIR-615 version 20.09, consider disabling access to the web interface until a patch is available to prevent exploitation of the Cross-Site Request Forgery issue. Restrict access to the router's configuration page to minimize the risk of unauthorized changes. Avoid using the router's web interface for sensitive operations until the issue is resolved.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-7398

Produtos afetados

D-Link Dir-615