5.8
CVSSv3

CVE-2018-15516

Published: 31/01/2019 Updated: 26/04/2023
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.8 | Impact Score: 4 | Exploitability Score: 1.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N

Vulnerability Summary

The FTP service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices allows remote malicious users to conduct a PORT command bounce scan via port 8000, resulting in SSRF.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dlink central wifimanager 1.03

Exploits

The FTP Server component of the D-LINK Central WifiManager can be used as a man-in-the-middle machine allowing PORT Command bounce scan attacks This vulnerability allows remote attackers to abuse your network and discreetly conduct network port scanning Victims will then think these scans are originating from the D-LINK network running the afflic ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2018-15516 / D- LINK Central WifiManager CWM-100 / FTP Server PORT Bounce Scan <!--X-Subject-Header-End--> <!--X-H ...