6.8
CVSSv2

CVE-2012-1308

Published: 08/10/2012 Updated: 29/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in redpass.cgi in D-Link DSL-2640B Firmware EU_4.00 allows remote malicious users to hijack the authentication of administrators for requests that change the administrator password via the sysPassword parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

dlink dsl-2640b_firmware 4.00

dlink dsl-2640b -

Exploits

+--------------------------------------------------------------------------------------------------------------------------------+ # Exploit Title : D-Link DSL-2640B (ADSL Router) CSRF Vulnerability # Date : 19-02-2012 # Author : Ivano Binetti (ivanobinetticom) # Vendor site : wwwd-linkcom # Version : DSL-26 ...