PT-2019-8634 · D Link+1 · D-Link Dcs-1130+1

Mandar Satam

·

Published

2019-07-02

·

Updated

2021-04-26

·

CVE-2017-8411

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DCS-1130 devices (affected versions not specified)
Description An issue was discovered on D-Link DCS-1130 devices, where the device provides a user with the capability of setting a SMB folder for the video clippings recorded by the device. The POST parameters passed in this request result in being passed as commands to a "system" API in the function, thus resulting in command injection on the device. The library "libmailutils.so" has the vulnerable function "sub 1FC4" that receives the values sent by the POST request. The value set in POST parameter receiver1 is extracted in function "sub 15AC" which is then passed to the vulnerable system API call. The vulnerable library function is accessed in "cgibox" binary at address 0x00023BCC which calls the "Send mail" function in "libmailutils.so" binary, resulting in the vulnerable POST parameter being passed to the library and causing the command injection issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-8411

Affected Products

D-Link Dcs-1130
Libmailutils.So