6.8
CVSSv2

CVE-2017-7851

Published: 15/11/2017 Updated: 26/04/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

D-Link DCS-936L devices with firmware prior to 1.05.07 have an inadequate CSRF protection mechanism that requires the device's IP address to be a substring of the HTTP Referer header.

Vulnerable Product Search on Vulmon Subscribe to Product

d-link dcs-936l

Exploits

# Exploit Title: [D-Link DCS-936L network camera incomplete/weak CSRF protection vulnerability] # Date: [26/03/2017] # Exploit Author: [SlidingWindow] , Twitter: @Kapil_Khot # Vendor Homepage: [usdlinkcom/product-category/home-solutions/view/network-cameras/] # Version: [Tested on DCS-936L with firmware version 103 Other versions/models ...
D-Link DCS-936L suffers from a cross site request forgery vulnerability ...