CVE-2017-7851: CSRF
D-Link DCS-936L devices with firmware before 1.05.07 have an inadequate CSRF protection mechanism that requires the device's IP address to be a substring of the HTTP Referer header.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7851?
The severity of CVE-2017-7851 is high.
What is CVE-2017-7851?
CVE-2017-7851 is a vulnerability in D-Link DCS-936L devices with firmware before 1.05.07 that has an inadequate CSRF protection mechanism.
How does CVE-2017-7851 affect D-Link DCS-936L devices?
CVE-2017-7851 affects D-Link DCS-936L devices with firmware before 1.05.07 by having an inadequate CSRF protection mechanism.
How can I fix CVE-2017-7851?
To fix CVE-2017-7851, update the firmware of the D-Link DCS-936L device to version 1.05.07 or higher.
Where can I find more information about CVE-2017-7851?
More information about CVE-2017-7851 can be found at the following link: [https://www.qualys.com/2017/03/26/qsa-2017-03-26/qsa-2017-03-26.pdf](https://www.qualys.com/2017/03/26/qsa-2017-03-26/qsa-2017-03-26.pdf)