Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Rigan

#21142of 53,624
11.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2012-5918
6.8
2012-10-08
D Link · Dcs-900 · CVE-2012-5319
**Name of the Vulnerable Software and Affected Versions** D-Link DCS-900, DCS-2000, and DCS-5300 (affected versions not specified) **Description** A cross-site request forgery (CSRF) issue exists, allowing remote attackers to hijack administrator authentication for requests that change the administrator password via the `rootpass` parameter in the setup/security.cgi endpoint. **Recommendations** For D-Link DCS-900, DCS-2000, and DCS-5300, as a temporary workaround, consider restricting access to the setup/security.cgi endpoint to minimize the risk of exploitation. Avoid using the `rootpass` parameter in this endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2012-2936
5.0
2012-01-20
Airties · Airties Air 4450 · CVE-2012-0902
**Name of the Vulnerable Software and Affected Versions** AirTies Air 4450 version 1.1.2.18 **Description** The issue allows remote attackers to cause a denial of service, resulting in a reboot of the device, by sending a direct request to the "cgi-bin/loader" endpoint. **Recommendations** For AirTies Air 4450 version 1.1.2.18, consider restricting access to the "cgi-bin/loader" endpoint to prevent remote attackers from causing a denial of service.