First published: Wed Nov 15 2017(Updated: )
D-Link DCS-936L devices with firmware before 1.05.07 have an inadequate CSRF protection mechanism that requires the device's IP address to be a substring of the HTTP Referer header.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link DCS-936L | <1.05.07 | |
Dlink Dcs-936l |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-7851 is high.
CVE-2017-7851 is a vulnerability in D-Link DCS-936L devices with firmware before 1.05.07 that has an inadequate CSRF protection mechanism.
CVE-2017-7851 affects D-Link DCS-936L devices with firmware before 1.05.07 by having an inadequate CSRF protection mechanism.
To fix CVE-2017-7851, update the firmware of the D-Link DCS-936L device to version 1.05.07 or higher.
More information about CVE-2017-7851 can be found at the following link: [https://www.qualys.com/2017/03/26/qsa-2017-03-26/qsa-2017-03-26.pdf](https://www.qualys.com/2017/03/26/qsa-2017-03-26/qsa-2017-03-26.pdf)