Inadequate CSRF Protection in D-Link DCS-936L Devices with Firmware Before 1.05.07

Inadequate CSRF Protection in D-Link DCS-936L Devices with Firmware Before 1.05.07

CVE-2017-7851 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

D-Link DCS-936L devices with firmware before 1.05.07 have an inadequate CSRF protection mechanism that requires the device's IP address to be a substring of the HTTP Referer header.

Learn more about our Web Application Penetration Testing UK.