CVE-2017-7404
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
On the D-Link DIR-615 before v20.12PTb04, if a victim logged in to the Router's Web Interface visits a malicious site from another Browser tab, the malicious site then can send requests to the victim's Router without knowing the credentials (CSRF). An attacker can host a page that sends a POST request to Form2File.htm that tries to upload Firmware to victim's Router. This causes the router to reboot/crash resulting in Denial of Service. An attacker may succeed in uploading malicious Firmware.
En D-Link DIR-615 en versiones anteriores a v20.12PTb04, si una víctima con sesión iniciada en la interfaz web del router visita un sitio malicioso desde otra pestaña Browser, el sitio malicioso podría enviar peticiones al router de la víctima sin conocer las credenciales (CSRF). Un atacante podría alojar una página que envía una petición POST a Form2File.htm que intenta subir firmware al router de la víctima. Esto provoca que el router se reinicie/cierre inesperadamente, resultando en una denegación de servicio. Un atacante podría tener éxito a la hora de subir firmware malicioso.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-04-03 CVE Reserved
- 2017-07-07 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://www.qualys.com/2017/03/12/qsa-2017-03-12/qsa-2017-03-12.pdf | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
ftp://ftp2.dlink.com/SECURITY_ADVISEMENTS/DIR-615/REVT/DIR-615_REVT_FIRMWARE_PATCH_v20.12PTb04.zip | 2021-04-23 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dlink Search vendor "Dlink" | Dir-615 Search vendor "Dlink" for product "Dir-615" | <= 20.12ptb01 Search vendor "Dlink" for product "Dir-615" and version " <= 20.12ptb01" | - |
Affected
| in | Dlink Search vendor "Dlink" | Dir-615 Search vendor "Dlink" for product "Dir-615" | - | - |
Safe
|