Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ppfw-543c-9q84

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php.

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php.

EPSS

Процентиль: 97%
0.40758
Средний

8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
nvd
около 11 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php.

CVSS3: 8.3
fstec
почти 12 лет назад

Уязвимость микропрограммного обеспечения маршрутизатора D-Link DIR-600, связанная с подделкой межсайтовых запросов, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 97%
0.40758
Средний

8 High

CVSS3

Дефекты

CWE-352