D-Link DIR-615 Multiple Remote Security Vulnerabilities
BID:57882
Info
D-Link DIR-615 Multiple Remote Security Vulnerabilities
| Bugtraq ID: | 57882 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 11 2013 12:00AM |
| Updated: | May 20 2013 10:23AM |
| Credit: | Michael Messner |
| Vulnerable: |
D-Link DIR-615 0 |
| Not Vulnerable: | |
Discussion
D-Link DIR-615 Multiple Remote Security Vulnerabilities
D-Link DIR-615 is prone to multiple security vulnerabilities, including:
1. A remote command-injection vulnerability
2. An information-disclosure vulnerability
3. A cross-site request-forgery vulnerability
Exploiting these issues could allow an attacker to disclose sensitive information, perform arbitrary actions, or execute arbitrary commands in the context of the affected device.
D-Link DIR-615 is prone to multiple security vulnerabilities, including:
1. A remote command-injection vulnerability
2. An information-disclosure vulnerability
3. A cross-site request-forgery vulnerability
Exploiting these issues could allow an attacker to disclose sensitive information, perform arbitrary actions, or execute arbitrary commands in the context of the affected device.
Exploit / POC
D-Link DIR-615 Multiple Remote Security Vulnerabilities
Attackers can use a browser to exploit these issues. To exploit the cross-site request-forgery vulnerability an attacker must entice an unsuspecting victim into following a malicious URI.
Example URIs and requests are available. Please see the references for more information.
The following example exploit code is available:
Attackers can use a browser to exploit these issues. To exploit the cross-site request-forgery vulnerability an attacker must entice an unsuspecting victim into following a malicious URI.
Example URIs and requests are available. Please see the references for more information.
The following example exploit code is available:
Solution / Fix
D-Link DIR-615 Multiple Remote Security Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].