PT-2018-2192 · D Link · D-Link Central Wifimanager Cwm-100

Hyp3Rlinx

+1

·

Published

2018-08-09

·

Updated

2023-04-26

·

CVE-2018-15516

CVSS v3.1

5.8

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions D-Link Central WiFiManager CWM-100 version 1.03 r0098
Description The issue is related to the FTP service, which allows remote attackers to conduct a PORT command bounce scan via port 8000, resulting in a Server-Side Request Forgery (SSRF) attack. This can also lead to network port scanning and potentially enable a man-in-the-middle attack. The vulnerability is associated with incorrect security requirements of the FTP Server component.
Recommendations For D-Link Central WiFiManager CWM-100 version 1.03 r0098, consider disabling the FTP service until a patch is available to prevent exploitation. Restrict access to port 8000 to minimize the risk of SSRF attacks.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

BDU:2019-00170
CVE-2018-15516

Affected Products

D-Link Central Wifimanager Cwm-100