CVE-2013-3095

D-Link DIR865L <1.05b07 - CSRF

Title source: llm

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR865L router (Rev. A1) with firmware before 1.05b07 allow remote attackers to hijack the authentication of administrators for requests that (1) change the administrator password or (2) enable remote management via a request to hedwig.cgi or (3) activate configuration changes via a request to pigwidgeon.cgi.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Jacob Holcomb · htmlremotehardware
https://www.exploit-db.com/exploits/38481

Scores

EPSS 0.0094
EPSS Percentile 76.3%

Details

CWE
CWE-352
Status published
Products (5)
dlink/dir865l
dlink/dir865l_firmware 1.00b24
dlink/dir865l_firmware 1.02
dlink/dir865l_firmware 1.03
dlink/dir865l_firmware < 1.05
Published Nov 20, 2013
Tracked Since Feb 18, 2026