ID

VAR-201403-0620


TITLE

D-Link DSL-2640U Cross-site request forgery vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-201403-572

DESCRIPTION

D-Link DSL-2640U is a router product of D-Link. A cross-site request forgery vulnerability exists in D-Link DSL-2640U 1.0.24WW and earlier versions. A remote attacker could use this vulnerability to perform unauthorized operations. D-Link DSL-2640U is prone to multiple cross-site request-forgery vulnerabilities. This may lead to further attacks. D-Link DSL-2640U 1.0.24WW and prior are vulnerable

Trust: 0.81

sources: CNNVD: CNNVD-201403-572 // BID: 66091

AFFECTED PRODUCTS

vendor:d linkmodel:dsl-2640uscope:eqversion:1.0.24

Trust: 0.3

sources: BID: 66091

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201403-572

TYPE

cross-site request forgery

Trust: 0.6

sources: CNNVD: CNNVD-201403-572

EXTERNAL IDS

db:BIDid:66091

Trust: 0.9

db:CNNVDid:CNNVD-201403-572

Trust: 0.6

db:DLINKid:SAP10015

Trust: 0.3

sources: BID: 66091 // CNNVD: CNNVD-201403-572

REFERENCES

url:http://www.securityfocus.com/bid/66091

Trust: 0.6

url:http://www.dlink.com/

Trust: 0.3

url:http://securityadvisories.dlink.com/security/publication.aspx?name=sap10015

Trust: 0.3

sources: BID: 66091 // CNNVD: CNNVD-201403-572

CREDITS

TeaM MosTa

Trust: 0.9

sources: BID: 66091 // CNNVD: CNNVD-201403-572

SOURCES

db:BIDid:66091
db:CNNVDid:CNNVD-201403-572

LAST UPDATE DATE

2022-05-17T02:09:50.029000+00:00


SOURCES UPDATE DATE

db:BIDid:66091date:2014-03-10T00:00:00
db:CNNVDid:CNNVD-201403-572date:2014-04-01T00:00:00

SOURCES RELEASE DATE

db:BIDid:66091date:2014-03-10T00:00:00
db:CNNVDid:CNNVD-201403-572date:2014-03-10T00:00:00