CVE-2017-7851
HIGHD-Link DCS-936L < 1.05.07 - Cross-Site Request Forgery via Referer Header Validation Bypass
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-7851. PoCs published by SlidingWindow.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in D-Link DCS-936L cameras (firmware 1.02.01) due to weak Referer header validation. The PoC HTML form submits a request to add a new admin user, bypassing authentication by embedding the target IP in the Referer header.
Description
D-Link DCS-936L devices with firmware before 1.05.07 have an inadequate CSRF protection mechanism that requires the device's IP address to be a substring of the HTTP Referer header.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in D-Link DCS-936L cameras (firmware 1.02.01) due to weak Referer header validation. The PoC HTML form submits a request to add a new admin user, bypassing authentication by embedding the target IP in the Referer header.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H