CVE-2016-10405: Critical severity D-Link Dir-600l Firmware vulnerability
Published Sep 7, 2017
·Updated
Session fixation vulnerability in D-Link DIR-600L routers (rev. Ax) with firmware before FW1.17.B01 allows remote attackers to hijack web sessions via unspecified vectors.
Affected Software
2 affected components
D-Link Dir-600l Firmware<=1.16
Dlink Dir-600l
Event History
Sep 7, 2017
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10405?
The severity of CVE-2016-10405 is considered high due to the potential for remote attackers to hijack web sessions.
2
How do I fix CVE-2016-10405?
To fix CVE-2016-10405, upgrade your D-Link DIR-600L router to firmware version FW1.17.B01 or later.
3
What type of vulnerability is CVE-2016-10405?
CVE-2016-10405 is a session fixation vulnerability that allows the hijacking of web sessions.
4
Which devices are affected by CVE-2016-10405?
CVE-2016-10405 specifically affects D-Link DIR-600L routers with firmware versions before FW1.17.B01.
5
Can CVE-2016-10405 be exploited remotely?
Yes, CVE-2016-10405 can be exploited remotely by attackers to hijack web sessions without physical access.