First published: Thu Dec 26 2019(Updated: )
D-Link DIR-601 B1 2.00NA devices have CSRF because no anti-CSRF token is implemented. A remote attacker could exploit this in conjunction with CVE-2019-16327 to enable remote router management and device compromise. NOTE: this is an end-of-life product.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link DIR-601 Firmware | =2.00na | |
dlink DIR-601 firmware | =b1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-16326 is classified as a medium severity vulnerability that allows CSRF attacks.
To mitigate CVE-2019-16326, it is recommended to update to a newer router model since this product has reached end-of-life and is no longer supported.
CVE-2019-16326 affects D-Link DIR-601 B1 devices with firmware version 2.00NA.
Yes, CVE-2019-16326 can be exploited remotely when used in conjunction with CVE-2019-16327.
CVE-2019-16326 enables Cross-Site Request Forgery (CSRF) attacks, potentially allowing remote router management.