Skip to main content
High November 15, 2009

D-Link WBR-1310 Cross-Site Scripting

The D-Link WBR-1310 router reflects unsanitised input in its ping diagnostic page. Because the password-change endpoint does not require the current password, the same XSS payload can silently reset the admin credential and take over the router.

CVSS Score

8.8 / 10.0

Severity

High

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Advisory

DeviceD-Link WBR-1310
Firmware4.00
ImpactChange admin password, full router takeover
Websec AdvisoryWS10-04

Background

The D-Link WBR-1310 web administration interface does not validate or sanitize the majority of its input parameters. The ping diagnostic page (pingIP parameter) reflects user input directly into the response.

Description

Reflected XSS in the pingIP parameter lets an attacker run JavaScript in an authenticated admin's browser. Because the password-change endpoint does not require the current password, the same XSS payload can silently reset the admin credential and hand the router to the attacker.

Exploit / Proof of Concept

http://192.168.0.1/tools_vct.php?pingIP=<script>alert(0)</script>
http://192.168.0.1/tools_vct.xgi?pingIP=<script>alert(0)</script>

Workaround

Do not browse untrusted sites while logged into the router admin panel. Restrict the management interface to trusted hosts on the LAN.

Remediation

No vendor fix available at disclosure. Avoid exposing the admin panel and restrict LAN access to trusted hosts.

Share this advisory:

Related Security Advisories

Stay informed about other recent vulnerabilities and security advisories

Critical December 18, 2014

Command Execution and Backdoor in Zhone GPON-2520

This post will describe a backdoor account found in the Zhone GPON-2520 and will provide a PoC which can be used to disable the firewall filtration rules in order to allow access to services such as ssh, telnet and ftp.

Severity:
CVSS: 9.8
View advisory
High May 22, 2014

Huawei HG8245 / HG8247 WPA Generator

Huawei HG8245 & HG8247 ONT (firmware version V1R006C00S100) rely on a weak algorithm to calculate the WPA keys, keys can be predicted easily using the WiFi's MAC Address (BSSID).

Severity:
CVSS: 7.4
View advisory
High December 19, 2013

Arbitrary Command Execution in Alcatel-Lucent I-240W-Q

The Alcatel-Lucent I-240W-Q ONT's Diagnostics page does not filter shell metacharacters in the IP address field, allowing any authenticated administrator to execute arbitrary commands as root and fully compromise the device.

Severity:
CVSS: 8.0
View advisory