CVE-2017-7398
D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacker to perform an unwanted action on a wireless router for which the user/admin is currently authenticated, as demonstrated by changing the Security option from WPA2 to None, or changing the hiddenSSID parameter, SSID parameter, or a security-option password.
- Affected products
- D-Link Dir-615
- D-link dir-615 Firmware
- = 20.09
- Fix
- Available
- CVSS 3.0
- 8.8 HIGH
- EPSS
- 2.5% (83th percentile)
- Weakness
- CWE-352
- NVD status
- Modified
- Published
- 2017-04-04
CVE-2017-7398 at NVD
4 known exploits for CVE-2017-7398
Proof-of-concept code and exploit modules indexed by Sploitus