PT-2018-2191 · D Link · D-Link Central Wifimanager Cwm-100

Hyp3Rlinx

+1

·

Publicado

2018-08-08

·

Atualizado

2023-04-26

·

CVE-2018-15517

CVSS v3.1

8.6

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions D-Link Central WiFiManager CWM-100 version 1.03 r0098
Description The issue concerns the MailConnect feature, which is supposed to check connections to an SMTP server but actually allows outbound TCP to any port on any IP address. This leads to a Server-Side Request Forgery (SSRF) vulnerability, as demonstrated by a specific URI, "index.php/System/MailConnect/host/127.0.0.1/port/22/secure/". The vulnerability exists due to insufficient validation of incoming requests, potentially allowing a remote attacker to perform an SSRF attack.
Recommendations For D-Link Central WiFiManager CWM-100 version 1.03 r0098, consider disabling the MailConnect feature until a patch is available to prevent potential SSRF attacks. Restrict access to the MailConnect functionality to minimize the risk of exploitation. Avoid using the MailConnect feature with untrusted input until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-00169
CVE-2018-15517

Produtos afetados

D-Link Central Wifimanager Cwm-100