d-link DIR-816L Security Vulnerabilities

4 Vulnerabilities
Description

** UNSUPPORTED WHEN ASSIGNED ** webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: this is typically not exploitable because of URL encoding (except in Internet Explorer) and because a web page cannot specify that a client should make an additional HTTP request with an arbitrary Referer header.

Impacted versions: -

Base Score: 0.0, Severity: NA, ID: CVE-2020-25786, Last Modified: 2020-09-19T20:15:00Z

References

Advisory

Modemly Security Checklist

D-Link-DIR-816L-router-setup

An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker can perform command injection by injecting a payload into the Search Target (ST) field of the SSDP M-SEARCH discover packet.

Impacted versions: -

Base Score: 0.0, Severity: NA, ID: CVE-2020-15893, Last Modified: 2020-07-22T19:46:00Z

References

Advisory

Modemly Security Checklist

D-Link-DIR-816L-router-setup

An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. There exists an exposed administration function in getcfg.php, which can be used to call various services. It can be utilized by an attacker to retrieve various sensitive information, such as admin login credentials, by setting the value of _POST_SERVICES in the query string to DEVICE.ACCOUNT.

Impacted versions: -

Base Score: 0.0, Severity: NA, ID: CVE-2020-15894, Last Modified: 2020-07-22T19:46:00Z

References

Advisory

Modemly Security Checklist

D-Link-DIR-816L-router-setup

An XSS issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. In the file webinc/js/info.php, no output filtration is applied to the RESULT parameter, before it's printed on the webpage.

Impacted versions: -

Base Score: 0.0, Severity: NA, ID: CVE-2020-15895, Last Modified: 2020-07-22T19:46:00Z

References

Advisory

Modemly Security Checklist

D-Link-DIR-816L-router-setup
Free Home-Networking Courses, tutorials and security checklists

USAGE: Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.