ID:4501 - Exploit for Code Injection in Central WiFiManager - CVE-2019-13372
Published: August 19, 2020
Central WiFiManager
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation when processing cookie values in /web/Lib/Action/IndexAction.class.php script in D-Link Central WiFi Manager CWM(100). A remote attacker can send a specially crafted request and execute arbitrary PHP code on the device.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.