CVE-2017-7404

HIGH

D-Link DIR-615 < 20.12PTb01 - Cross-Site Request Forgery via Firmware Upload

Title source: llm
STIX 2.1

Description

On the D-Link DIR-615 before v20.12PTb04, if a victim logged in to the Router's Web Interface visits a malicious site from another Browser tab, the malicious site then can send requests to the victim's Router without knowing the credentials (CSRF). An attacker can host a page that sends a POST request to Form2File.htm that tries to upload Firmware to victim's Router. This causes the router to reboot/crash resulting in Denial of Service. An attacker may succeed in uploading malicious Firmware.

References (2)

Core 2

Scores

CVSS v3 8.8
EPSS 0.0031
EPSS Percentile 54.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (1)
dlink/dir-615 < 20.12ptb01
Published Jul 07, 2017
Tracked Since Feb 18, 2026