D-Link Central WifiManager 漏洞列表
共找到 1 个与 D-Link Central WifiManager 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2018-15517: D-Link Central WifiManager - Server-Side Request Forgery POC
D-Link Central WifiManager is susceptible to server-side request forgery. The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually allows outbound TCP to any port on any IP address, as demonstrated by an index.php/System/MailConnect/host/127.0.0.1/port/22/secure/ URI. This can undermine accountability of where scan or connections actually came from and or bypass the FW etc. This can be automated via script or using a browser.