CVE-2018-8898
CRITICALD-Link DSL-3782 Firmware - Unauthenticated Authentication Bypass in Login Panel
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-8898. PoCs published by Giulio Comi.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in D-Link DSL 3782 routers, allowing unauthorized access to sensitive endpoints and configuration changes via crafted HTTP requests. The PoC includes commands to retrieve session keys and modify router settings without proper authentication.
Description
A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B012" FWVer="3.10.0.24" FirmVer="TT_77616E6771696F6E67") allows unauthenticated attackers to perform arbitrary modification (read, write) to passwords and configurations meanwhile an administrator is logged into the web panel.
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in D-Link DSL 3782 routers, allowing unauthorized access to sensitive endpoints and configuration changes via crafted HTTP requests. The PoC includes commands to retrieve session keys and modify router settings without proper authentication.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H