Release date:
Updated on:
Affected Systems:
D-Link DIR-100 4.03B07
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65290
CVE (CAN) ID: CVE-2013-7051, CVE-2013-7052, CVE-2013-7053, CVE-2013-7054, CVE-2013-7055
D-Link DIR-100 is a small Broadband Router integrated with firewall functionality.
D-Link DIR-100 Ethernet Broadband Router does not properly restrict access to Administrator Web interface, cliget. cgi Script Access, and HTTP requests are not validated. There are multiple security vulnerabilities in implementation, attackers can exploit these vulnerabilities to access restricted functions, obtain administrator creden。 or other sensitive settings, and change the administrator password.
<* Source: Felix Richter
Link: http://www.securelist.com/en/advisories/56677
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
D-Link
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.dlink.com/
Refer:
D-Link:
Http://more.dlink.de/sicherheit/news.html
Felix Richter:
Http://pigstarter.krebsco.de/report/2013-12-18_dir100.txt