ZeroHour

CVE-2017-7851

PoC
CVSS 3.0
8.8 high
EPSS
2%p83
Published
()
Modified
Description

D-Link DCS-936L devices with firmware before 1.05.07 have an inadequate CSRF protection mechanism that requires the device's IP address to be a substring of the HTTP Referer header.

Vendors
d-link
Products
dcs-936l
Weakness
CWE-352
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.