PT-2019-8629 · D Link · D-Link Dcs-1130
Published
2019-07-02
·
Updated
2021-04-26
·
CVE-2017-8406
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
D-Link DCS-1130 devices (affected versions not specified)
Description
An issue was discovered where the device provides a crossdomain.xml file with no restrictions on who can access the webserver. This allows a hosted flash file on any domain to make calls to the device's webserver and pull any information stored on the device. In this case, user credentials are stored in clear text on the device and can be pulled easily. The device also lacks cross-site scripting forgery protection, allowing an attacker to trick a logged-in user into executing a cross-site flashing attack on their browser. This can execute any action on the device provided by the web management interface, stealing credentials from the
tools admin.cgi file's response and displaying them inside a Textfield.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D-Link Dcs-1130