PT-2019-8629 · D Link · D-Link Dcs-1130

Published

2019-07-02

·

Updated

2021-04-26

·

CVE-2017-8406

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions D-Link DCS-1130 devices (affected versions not specified)
Description An issue was discovered where the device provides a crossdomain.xml file with no restrictions on who can access the webserver. This allows a hosted flash file on any domain to make calls to the device's webserver and pull any information stored on the device. In this case, user credentials are stored in clear text on the device and can be pulled easily. The device also lacks cross-site scripting forgery protection, allowing an attacker to trick a logged-in user into executing a cross-site flashing attack on their browser. This can execute any action on the device provided by the web management interface, stealing credentials from the tools admin.cgi file's response and displaying them inside a Textfield.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-8406

Affected Products

D-Link Dcs-1130