First published: Thu May 10 2018(Updated: )
CSRF exists on D-Link DIR-868L devices, leading to (for example) a change to the Admin password. hedwig.cgi and pigwidgeon.cgi are two of the affected components.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-868l Firmware | =1.12 | |
Dlink Dir-868l |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10957 is a Cross-Site Request Forgery (CSRF) vulnerability that exists on D-Link DIR-868L devices.
The severity of CVE-2018-10957 is high, with a CVSS score of 8.8.
CVE-2018-10957 allows an attacker to perform actions on behalf of an authenticated user, such as changing the Admin password.
The affected components are hedwig.cgi and pigwidgeon.cgi.
As of now, there is no specific fix available for CVE-2018-10957. It is recommended to update to the latest firmware version provided by D-Link.