PT-2018-2076 · D Link · D-Link Central Wifi Manager

Julian Muñoz

·

Publicado

2018-06-04

·

Atualizado

2023-04-26

·

CVE-2018-17440

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link Central WiFi Manager versions prior to 1.03r0100-Beta1
Description The issue is related to the use of hardcoded credentials for the FTP service, which runs on port 9000. This allows a remote attacker to execute arbitrary PHP code by uploading a file to the web root directory and then accessing it. The hardcoded credentials used are admin for both the username and password.
Recommendations For versions prior to 1.03r0100-Beta1, update to version 1.03r0100-Beta1 or later to resolve the issue. As a temporary workaround, consider changing the default FTP credentials and restricting access to the FTP server on port 9000 to minimize the risk of exploitation.

Exploit

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-00026
CVE-2018-17440

Produtos afetados

D-Link Central Wifi Manager