D-Link DIR-600 and DIR-300 Multiple Security Vulnerabilities
BID:59405
Info
D-Link DIR-600 and DIR-300 Multiple Security Vulnerabilities
| Bugtraq ID: | 59405 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 22 2013 12:00AM |
| Updated: | Aug 08 2013 05:15AM |
| Credit: | Michael Messner |
| Vulnerable: |
D-Link DIR-300 1.05 |
| Not Vulnerable: | |
Discussion
D-Link DIR-600 and DIR-300 Multiple Security Vulnerabilities
D-Link DIR-600 and DIR-300 are prone to the following security vulnerabilities:
1. Multiple command-injection vulnerabilities
2. A cross-site request-forgery vulnerability
3. A cross-site scripting vulnerability
4. A password encryption weakness
5. Multiple information-disclosure vulnerabilities
6. An HTTP-header-injection vulnerability
7. A security-bypass vulnerability
An attacker can exploit these issues to gain access to potentially sensitive information, decrypt stored passwords, execute arbitrary commands in the context of the affected device, steal cookie-based authentication credentials, perform unauthorized actions in the context of a user session, or redirect users to arbitrary sites and perform HTTP-request smuggling. Other attacks are also possible.
D-Link DIR-600 and DIR-300 are prone to the following security vulnerabilities:
1. Multiple command-injection vulnerabilities
2. A cross-site request-forgery vulnerability
3. A cross-site scripting vulnerability
4. A password encryption weakness
5. Multiple information-disclosure vulnerabilities
6. An HTTP-header-injection vulnerability
7. A security-bypass vulnerability
An attacker can exploit these issues to gain access to potentially sensitive information, decrypt stored passwords, execute arbitrary commands in the context of the affected device, steal cookie-based authentication credentials, perform unauthorized actions in the context of a user session, or redirect users to arbitrary sites and perform HTTP-request smuggling. Other attacks are also possible.
Exploit / POC
D-Link DIR-600 and DIR-300 Multiple Security Vulnerabilities
An attacker can exploit these issues through readily available tools and a browser. To exploit the cross-site scripting and cross-sire request-forgery issues the attacker must entice an unsuspecting victim to follow a malicious URI.
The following metasploit module is available:
An attacker can exploit these issues through readily available tools and a browser. To exploit the cross-site scripting and cross-sire request-forgery issues the attacker must entice an unsuspecting victim to follow a malicious URI.
The following metasploit module is available:
Solution / Fix
D-Link DIR-600 and DIR-300 Multiple Security Vulnerabilities
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
D-Link DIR-600 and DIR-300 Multiple Security Vulnerabilities
References:
References:
- D-Link DIR-615 Homepage (D-Link)
- D-Link Homepage (D-Link)