First published: Tue Jul 02 2019(Updated: )
An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of changing the administrative password for the web management interface. It seems that the device does not implement any cross-site request forgery protection mechanism which allows an attacker to trick a user who is logged in to the web management interface to change the user's password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dcs-1130 Firmware | ||
Dlink Dcs-1130 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8407 is a vulnerability found on D-Link DCS-1130 devices that allows an attacker to change the administrative password without any cross-site request forgery protection.
CVE-2017-8407 has a severity rating of 8.8, which is considered high.
The affected software is D-Link DCS-1130 firmware.
Yes, D-Link DCS-1130 devices are vulnerable to CVE-2017-8407.
To fix CVE-2017-8407, it is recommended to apply the latest firmware updates provided by D-Link.