CVE-2017-8407: CSRF
An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of changing the administrative password for the web management interface. It seems that the device does not implement any cross-site request forgery protection mechanism which allows an attacker to trick a user who is logged in to the web management interface to change the user's password.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-8407?
CVE-2017-8407 is a vulnerability found on D-Link DCS-1130 devices that allows an attacker to change the administrative password without any cross-site request forgery protection.
How severe is CVE-2017-8407?
CVE-2017-8407 has a severity rating of 8.8, which is considered high.
What is the affected software by CVE-2017-8407?
The affected software is D-Link DCS-1130 firmware.
Is D-Link DCS-1130 vulnerable to CVE-2017-8407?
Yes, D-Link DCS-1130 devices are vulnerable to CVE-2017-8407.
How can the vulnerability CVE-2017-8407 be fixed?
To fix CVE-2017-8407, it is recommended to apply the latest firmware updates provided by D-Link.