D-Link DIR-635 Multiple Security Vulnerabilities
BID:59514
Info
D-Link DIR-635 Multiple Security Vulnerabilities
| Bugtraq ID: | 59514 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 26 2013 12:00AM |
| Updated: | Apr 26 2013 12:00AM |
| Credit: | Michael Messner |
| Vulnerable: |
D-Link DIR-635 2.34EU |
| Not Vulnerable: | |
Discussion
D-Link DIR-635 Multiple Security Vulnerabilities
D-Link DIR-635 is prone to the following security vulnerabilities:
1. An HTML-injection vulnerability
2. A cross-site request-forgery vulnerability
3. A cross-site scripting vulnerability
4. A security-bypass vulnerability
An attacker can exploit these issues to execute HTML and arbitrary script code in the browser of an unsuspecting user in the context of the affected device, steal cookie-based authentication credentials, and perform unauthorized actions in the context of a user session. Other attacks are also possible.
D-Link DIR-635 is prone to the following security vulnerabilities:
1. An HTML-injection vulnerability
2. A cross-site request-forgery vulnerability
3. A cross-site scripting vulnerability
4. A security-bypass vulnerability
An attacker can exploit these issues to execute HTML and arbitrary script code in the browser of an unsuspecting user in the context of the affected device, steal cookie-based authentication credentials, and perform unauthorized actions in the context of a user session. Other attacks are also possible.
Exploit / POC
D-Link DIR-635 Multiple Security Vulnerabilities
An attacker can exploit these issues through readily available tools and a browser. To exploit the cross-site scripting and cross-sire request-forgery issues the attacker must entice an unsuspecting victim to follow a malicious URI.
An attacker can exploit these issues through readily available tools and a browser. To exploit the cross-site scripting and cross-sire request-forgery issues the attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
D-Link DIR-635 Multiple Security Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].