DD-WRT Cross-Site Request Forgery Vulnerability
BID:32703
Info
DD-WRT Cross-Site Request Forgery Vulnerability
| Bugtraq ID: | 32703 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2008 12:00AM |
| Updated: | Dec 11 2008 06:31PM |
| Credit: | Michael Brooks |
| Vulnerable: |
DD-WRT DD-WRT v24-sp1 |
| Not Vulnerable: | |
Discussion
DD-WRT Cross-Site Request Forgery Vulnerability
DD-WRT is prone to a cross-site request-forgery vulnerability.
Successful exploits will allow attackers to run arbitrary commands with administrative privileges, change web administration password, enable remote administration and create port forwarding rules to bypass the NAT. Other attacks are also possible.
DD-WRT v24-sp1 is vulnerable; other versions may also be affected.
DD-WRT is prone to a cross-site request-forgery vulnerability.
Successful exploits will allow attackers to run arbitrary commands with administrative privileges, change web administration password, enable remote administration and create port forwarding rules to bypass the NAT. Other attacks are also possible.
DD-WRT v24-sp1 is vulnerable; other versions may also be affected.
Exploit / POC
DD-WRT Cross-Site Request Forgery Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following exploit is available:
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following exploit is available:
Solution / Fix
DD-WRT Cross-Site Request Forgery Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Update (Dec. 11, 2008): The vendor has released updates to address this issue. However, further reports indicate the fixes do not properly address the issue.
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Update (Dec. 11, 2008): The vendor has released updates to address this issue. However, further reports indicate the fixes do not properly address the issue.
References
DD-WRT Cross-Site Request Forgery Vulnerability
References:
References: