CVE-2018-10957: CSRF
Published May 10, 2018
·Updated
CSRF exists on D-Link DIR-868L devices, leading to (for example) a change to the Admin password. hedwig.cgi and pigwidgeon.cgi are two of the affected components.
Affected Software
2 affected components
Dlink Dir-868l Firmware=1.12
Dlink DIR-868L
Event History
May 10, 2018
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is CVE-2018-10957?
CVE-2018-10957 is a Cross-Site Request Forgery (CSRF) vulnerability that exists on D-Link DIR-868L devices.
2
What is the severity of CVE-2018-10957?
The severity of CVE-2018-10957 is high, with a CVSS score of 8.8.
3
How does CVE-2018-10957 affect D-Link DIR-868L devices?
CVE-2018-10957 allows an attacker to perform actions on behalf of an authenticated user, such as changing the Admin password.
4
Which components are affected by CVE-2018-10957 on D-Link DIR-868L devices?
The affected components are hedwig.cgi and pigwidgeon.cgi.
5
Is there a fix available for CVE-2018-10957?
As of now, there is no specific fix available for CVE-2018-10957. It is recommended to update to the latest firmware version provided by D-Link.