PT-2018-2192 · D Link · D-Link Central Wifimanager Cwm-100
Hyp3Rlinx
+1
·
Publicado
2018-08-09
·
Atualizado
2023-04-26
·
CVE-2018-15516
CVSS v3.1
5.8
Média
| Vetor | AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
D-Link Central WiFiManager CWM-100 version 1.03 r0098
Description
The issue is related to the FTP service, which allows remote attackers to conduct a PORT command bounce scan via port 8000, resulting in a Server-Side Request Forgery (SSRF) attack. This can also lead to network port scanning and potentially enable a man-in-the-middle attack. The vulnerability is associated with incorrect security requirements of the FTP Server component.
Recommendations
For D-Link Central WiFiManager CWM-100 version 1.03 r0098, consider disabling the FTP service until a patch is available to prevent exploitation. Restrict access to port 8000 to minimize the risk of SSRF attacks.
Exploit
Correção
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
D-Link Central Wifimanager Cwm-100