Media Summary: Information disclosure in /htdocs/web/getcfg.php. Command injection by injecting a payload into the Search Target (ST) field of the SSDP M-SEARCH discover packet. Download binary config file containing cleartext credentials through directory traversal (/tmp/csman/0) and gain administrative ...
D Link Dir 645 Authentication Bypass Vulnerability - Detailed Analysis & Overview
Information disclosure in /htdocs/web/getcfg.php. Command injection by injecting a payload into the Search Target (ST) field of the SSDP M-SEARCH discover packet. Download binary config file containing cleartext credentials through directory traversal (/tmp/csman/0) and gain administrative ... Command execution via ddnshostname and ddnusername parameters in POST request to ddns_check.ccp. Affected Devices: ...