Record summary

CVE-2018-15517 has a selected CVSS score of 8.6 (high); EIP currently links 1 Nuclei template.

Description

The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually allows outbound TCP to any port on any IP address, leading to SSRF, as demonstrated by an index.php/System/MailConnect/host/127.0.0.1/port/22/secure/ URI.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 4, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHD-Link Central WifiManager - Server-Side Request ForgeryCVSS 8.6

D-Link Central WifiManager is susceptible to server-side request forgery. The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually allows outbound TCP to any port on any IP address, as demonstrated by an index.php/System/MailConnect/host/127.0.0.1/port/22/secure/ URI. This can undermine accountability of where scan or connections actually came from and or bypass the FW etc. This can be automated via script or using a browser.

Impact

Successful exploitation of this vulnerability could lead to unauthorized access to internal resources, data leakage, and potential compromise of the entire network.

Remediation

Apply the latest security patches or updates provided by D-Link to fix the SSRF vulnerability in Central WifiManager.

WeaknessesCWE-918
Authorsgy741
Template tagscvecve2018seclistspacketstormdlinkssrfoastvkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
CPE: cpe:2.3:a:dlink:central_wifimanager:1.03:r0098:*:*:*:*:*:*

Source: ProjectDiscovery

References

3