CVE-2013-5730
D-Link DSL-2740B Firmware EU_1.00 - Cross-Site Request Forgery via Wireless MAC Filter, Firewall, or Remote Management
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-5730. PoCs published by Ivano Binetti.
AI-analyzed exploit summary This exploit demonstrates CSRF vulnerabilities in D-Link DSL-2740B routers, allowing unauthorized changes to wireless MAC filtering, firewall protections, and remote management settings via crafted HTML forms.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DSL-2740B Gateway with firmware EU_1.00 allow remote attackers to hijack the authentication of administrators for requests that (1) enable or disable Wireless MAC Address Filters via a wlFltMode action to wlmacflt.cmd, (2) enable or disable firewall protections via a request to scdmz.cmd, or (3) enable or disable remote management via a save action to scsrvcntr.cmd.
Exploits (1)
This exploit demonstrates CSRF vulnerabilities in D-Link DSL-2740B routers, allowing unauthorized changes to wireless MAC filtering, firewall protections, and remote management settings via crafted HTML forms.