Release date: 2011-12-11
Updated on: 2011-12-12
Affected Systems:
D-Link DSL-500T (ADSL Router)
Description:
--------------------------------------------------------------------------------
DSL-500T is an ADSL2 + terminal with routing function, it is connected to the computer through Ethernet interface, with powerful routing function, is the ideal choice for home, office and SOHO users.
D-Link DSL-500T ADSL Router in the implementation of predictable resource location, brute force speculation and Cross Site Request Forgery Vulnerability, attackers can exploit this vulnerability to change vro settings, brute-force password guesses, perform CSRF attacks, and remotely log on to Alibaba Cloud.
1) The control panel of the modem is located in the default path, default login name and password, which allows attackers to gain access through the Internet or CSRF;
2) There is no protection mechanism for brute-force guess attacks;
<* Source: MustLive (mustlive@websecurity.com.ua)
Link: http://marc.info /? L = full-disclosure & m = 132364471230387 & w = 2
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
D-Link
------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.dlink.com/