NETIS DL4322D Modem Router Multiple Remote Security Vulnerabilities
BID:70617
Info
NETIS DL4322D Modem Router Multiple Remote Security Vulnerabilities
| Bugtraq ID: | 70617 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 16 2014 12:00AM |
| Updated: | Oct 16 2014 12:00AM |
| Credit: | Akastep |
| Vulnerable: |
Netis Systems Netlis DL4322D |
| Not Vulnerable: | |
Discussion
NETIS DL4322D Modem Router Multiple Remote Security Vulnerabilities
NETIS DL4322D modem router is prone to following security vulnerabilities:
1. A cross-site scripting vulnerability
2. Multiple cross-site request-forgery vulnerabilities
3. Multiple denial-of-service vulnerabilities
4. An information-disclosure vulnerability
5. An authentication-bypass vulnerability
An attacker may exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, perform unauthorized actions,to crash the affected application, denying service to legitimate users, to bypass the authentication mechanism and log in to the device and to obtain sensitive information such as user credentials for the system; that may lead to further attacks.
NETIS DL4322D modem router is prone to following security vulnerabilities:
1. A cross-site scripting vulnerability
2. Multiple cross-site request-forgery vulnerabilities
3. Multiple denial-of-service vulnerabilities
4. An information-disclosure vulnerability
5. An authentication-bypass vulnerability
An attacker may exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, perform unauthorized actions,to crash the affected application, denying service to legitimate users, to bypass the authentication mechanism and log in to the device and to obtain sensitive information such as user credentials for the system; that may lead to further attacks.
Exploit / POC
NETIS DL4322D Modem Router Multiple Remote Security Vulnerabilities
An attacker can exploit these issues using browser. To exploit cross-site scripting and cross-site request-forgery issues an attacker must entice an unsuspecting victim into following a malicious URI or visiting a malicious website.
An attacker can exploit these issues using browser. To exploit cross-site scripting and cross-site request-forgery issues an attacker must entice an unsuspecting victim into following a malicious URI or visiting a malicious website.
Solution / Fix
NETIS DL4322D Modem Router Multiple Remote Security Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
NETIS DL4322D Modem Router Multiple Remote Security Vulnerabilities
References:
References:
- Netlis DL4322D download page (Netlis)
- Netlis DL4322D HomePage (Netlis)