PT-2018-2192 · D Link · D-Link Central Wifimanager Cwm-100
Hyp3Rlinx
+1
·
Published
2018-08-09
·
Updated
2023-04-26
·
CVE-2018-15516
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
D-Link Central WiFiManager CWM-100 version 1.03 r0098
Description
The issue is related to the FTP service, which allows remote attackers to conduct a PORT command bounce scan via port 8000, resulting in a Server-Side Request Forgery (SSRF) attack. This can also lead to network port scanning and potentially enable a man-in-the-middle attack. The vulnerability is associated with incorrect security requirements of the FTP Server component.
Recommendations
For D-Link Central WiFiManager CWM-100 version 1.03 r0098, consider disabling the FTP service until a patch is available to prevent exploitation. Restrict access to port 8000 to minimize the risk of SSRF attacks.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Central Wifimanager Cwm-100