D-Link Routers Multiple Security Vulnerabilities
BID:67416
Info
D-Link Routers Multiple Security Vulnerabilities
| Bugtraq ID: | 67416 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 08 2014 12:00AM |
| Updated: | May 08 2014 12:00AM |
| Credit: | Kyle Lovett |
| Vulnerable: |
D-Link DIR-855L 1.02b08 D-Link DIR-835 1.04b04 D-Link DIR-652 2.0 D-Link DIR-652 1.06b05 D-Link DHP-1565 1.01 D-Link DGL-5500 1.12b02 |
| Not Vulnerable: | |
Discussion
D-Link Routers Multiple Security Vulnerabilities
D-Link DIR-652, DIR-835, DIR-855L, DGL-5500 and DHP-1565 routers are prone to the following security vulnerabilities:
1. A password-disclosure vulnerability
2. Multiple cross-site scripting vulnerabilities
3. Multiple information disclosure vulnerabilities
An attacker can exploit these issues to execute HTML and arbitrary script code in the browser of an unsuspecting user in the context of the affected device, steal cookie-based authentication credentials, or gain access to potentially sensitive information. Other attacks are also possible.
D-Link DIR-652, DIR-835, DIR-855L, DGL-5500 and DHP-1565 routers are prone to the following security vulnerabilities:
1. A password-disclosure vulnerability
2. Multiple cross-site scripting vulnerabilities
3. Multiple information disclosure vulnerabilities
An attacker can exploit these issues to execute HTML and arbitrary script code in the browser of an unsuspecting user in the context of the affected device, steal cookie-based authentication credentials, or gain access to potentially sensitive information. Other attacks are also possible.
Exploit / POC
D-Link Routers Multiple Security Vulnerabilities
An attacker can exploit these issues through readily available tools and a browser. To exploit a cross-site scripting issues, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example data is available:
An attacker can exploit these issues through readily available tools and a browser. To exploit a cross-site scripting issues, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following example data is available: