ID:4501 - Exploit for Code Injection in Central WiFiManager - CVE-2019-13372

 
Main Vulnerability Database Exploits ID:4501 - Exploit for Code Injection in Central WiFiManager - CVE-2019-13372

ID:4501 - Exploit for Code Injection in Central WiFiManager - CVE-2019-13372

Published: August 19, 2020


Vulnerability identifier: #VU45778
Vulnerability risk: High
CVE-ID: CVE-2019-13372
CWE-ID: CWE-94
Exploitation vector: Remote access
Vulnerable software:
Central WiFiManager

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation when processing cookie values in /web/Lib/Action/IndexAction.class.php script in D-Link Central WiFi Manager CWM(100). A remote attacker can send a specially crafted request and execute arbitrary PHP code on the device.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install updates from vendor's website.