Vulnerabilities > CVE-2018-15516 - Server-Side Request Forgery (SSRF) vulnerability in Dlink Central Wifimanager 1.03

047910
CVSS 5.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
HIGH
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
high complexity
dlink
CWE-918

Summary

The FTP service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices allows remote attackers to conduct a PORT command bounce scan via port 8000, resulting in SSRF.

Vulnerable Configurations

Part Description Count
Application
Dlink
1

Common Weakness Enumeration (CWE)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/150242/DLINK-CENTRAL-WIFI-MANAGER-CWM-100-FTP-SERVER-PORT-BOUNCE-SCAN.txt
idPACKETSTORM:150242
last seen2018-11-10
published2018-11-09
reporterhyp3rlinx
sourcehttps://packetstormsecurity.com/files/150242/D-LINK-Central-WifiManager-CWM-100-1.03-r0098-Man-In-The-Middle.html
titleD-LINK Central WifiManager (CWM 100) 1.03 r0098 Man-In-The-Middle