Code Injection in Central WiFiManager - CVE-2019-13372

 

Code Injection in Central WiFiManager - CVE-2019-13372

Published: August 19, 2020


Vulnerability identifier: #VU45778
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13372
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation when processing cookie values in /web/Lib/Action/IndexAction.class.php script in D-Link Central WiFi Manager CWM(100). A remote attacker can send a specially crafted request and execute arbitrary PHP code on the device.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Central WiFiManager

How to mitigate CVE-2019-13372

Install updates from vendor's website.

Central WiFiManager - update to 1.03R0100_BETA6

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins