日前我发现了D-Link DIR 880L/865L/868L/860L路由器存在多个XSS和命令注入漏洞,最主要的问题是路由器未对用户输入进行检查,导致恶意数据请求被执行,最终被远程攻击者控制整个设备。
0x00 Product Description Dlink is a multinational networking equipment manufacturing corporation The Dlink 860L/865L/868L/880L are wireless "Cloud" Router The vulnerabilities details are as follows: Vendor: D-Link Devices: DIR-880 REVA / DIR-868 REVA / DIR-865 / DIR-860 REVA Firmware: DIR-880L_REVA_FIRMWARE_PATCH_108B04 DIR868LA1_FW112b04 DIR-865L_REVA_FIRMWARE_PAT