CSRF Vulnerability in D-Link DIR-868L Devices Allows Unauthorized Admin Password Change

CSRF Vulnerability in D-Link DIR-868L Devices Allows Unauthorized Admin Password Change

CVE-2018-10957 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

CSRF exists on D-Link DIR-868L devices, leading to (for example) a change to the Admin password. hedwig.cgi and pigwidgeon.cgi are two of the affected components.

Learn more about our Web Application Penetration Testing UK.