First published: Thu Jan 31 2019(Updated: )
The FTP service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices allows remote attackers to conduct a PORT command bounce scan via port 8000, resulting in SSRF.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Central Wifimanager | =1.03-r0098 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-15516 is medium with a severity value of 5.8.
CVE-2018-15516 is a vulnerability in the FTP service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices that allows remote attackers to conduct a PORT command bounce scan via port 8000, resulting in SSRF (Server Side Request Forgery).
CVE-2018-15516 affects D-Link Central WiFiManager CWM-100 1.03 r0098 devices by allowing remote attackers to conduct a PORT command bounce scan via port 8000, resulting in SSRF.
To fix CVE-2018-15516, it is recommended to update the D-Link Central WiFiManager CWM-100 software to a version that addresses the vulnerability or apply patches provided by the vendor.
Yes, you can find additional information on CVE-2018-15516 at the following references: [http://packetstormsecurity.com/files/150242/D-LINK-Central-WifiManager-CWM-100-1.03-r0098-Man-In-The-Middle.html](http://packetstormsecurity.com/files/150242/D-LINK-Central-WifiManager-CWM-100-1.03-r0098-Man-In-The-Middle.html), [http://seclists.org/fulldisclosure/2018/Nov/27](http://seclists.org/fulldisclosure/2018/Nov/27), [https://vimeo.com/299797225](https://vimeo.com/299797225)