CVE-2018-15517
D-Link central_wifimanager Server-Side Request Forgery (SSRF)
Record summary
CVE-2018-15517 has a selected CVSS score of 8.6 (high); EIP currently links 1 Nuclei template.
Description
The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually allows outbound TCP to any port on any IP address, leading to SSRF, as demonstrated by an index.php/System/MailConnect/host/127.0.0.1/port/22/secure/ URI.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 4, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
central_wifimanagerBrowse D-Link / central_wifimanager | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHD-Link Central WifiManager - Server-Side Request ForgeryCVSS 8.6
D-Link Central WifiManager is susceptible to server-side request forgery. The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually allows outbound TCP to any port on any IP address, as demonstrated by an index.php/System/MailConnect/host/127.0.0.1/port/22/secure/ URI. This can undermine accountability of where scan or connections actually came from and or bypass the FW etc. This can be automated via script or using a browser.
Impact
Successful exploitation of this vulnerability could lead to unauthorized access to internal resources, data leakage, and potential compromise of the entire network.
Remediation
Apply the latest security patches or updates provided by D-Link to fix the SSRF vulnerability in Central WifiManager.
Source: ProjectDiscovery