Belkin G Plus Router DHCP Client List HTML Injection Vulnerability
BID:24881
Info
Belkin G Plus Router DHCP Client List HTML Injection Vulnerability
| Bugtraq ID: | 24881 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3784 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 12 2007 12:00AM |
| Updated: | Apr 16 2015 06:11PM |
| Credit: | Nico Leidecker of Portcullis Computer Security Ltd. is credited with the discovery of this vulnerability. |
| Vulnerable: |
Belkin F5D7231-4 G Plus Router (firmware) 4.5.3 |
| Not Vulnerable: | |
Discussion
Belkin G Plus Router DHCP Client List HTML Injection Vulnerability
The Belkin G Plus Router is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue may allow an attacker to execute HTML and script code in the context of the device, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.
Firmware version 4.05.03 is vulnerable; other versions may also be affected.
The Belkin G Plus Router is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue may allow an attacker to execute HTML and script code in the context of the device, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.
Firmware version 4.05.03 is vulnerable; other versions may also be affected.
Exploit / POC
Belkin G Plus Router DHCP Client List HTML Injection Vulnerability
Attackers can exploit this by connecting to a vulnerable router and waiting for an unsuspecting administrator to view a DHCP client list.
Attackers can exploit this by connecting to a vulnerable router and waiting for an unsuspecting administrator to view a DHCP client list.
Solution / Fix
Belkin G Plus Router DHCP Client List HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Belkin G Plus Router DHCP Client List HTML Injection Vulnerability
References:
References:
- Belkin Homepage (Belkin)