PT-2018-2190 · D Link · D-Link Central Wifimanager Cwm-100
Hyp3Rlinx
+1
·
Publicado
2018-08-08
·
Atualizado
2019-10-03
·
CVE-2018-15515
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
D-Link Central WiFiManager CWM-100 version 1.03 r0098
Description
The issue is related to the CaptivelPortal service, which loads a Trojan horse
quserex.dll from the CaptivelPortal.exe subdirectory. This allows unprivileged local users to gain SYSTEM privileges. The vulnerability is also associated with errors in loading the quserex.dll library, which can be exploited to execute arbitrary code using a specially crafted file.Recommendations
For D-Link Central WiFiManager CWM-100 version 1.03 r0098, consider disabling the CaptivelPortal service as a temporary workaround until a patch is available. Restrict access to the
quserex.dll library to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
D-Link Central Wifimanager Cwm-100