Dlink central wifimanager cwm100 serverside request forgery Vulnerability / Exploit
/
/
/
Exploits / Vulnerability Discovered : 2018-11-12 |
Type : webapps |
Platform : hardware
This exploit / vulnerability Dlink central wifimanager cwm100 serverside request forgery is for educational purposes only and if it is used you will do on your own risk!
# [Security Issue]
# Using a web browser or script SSRF can be initiated against internal/external systems
# to conduct port scans by leveraging D-LINKs MailConnect component.
# The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended
# to check a connection to an SMTP server but actually allows outbound TCP to any port on any IP address,
# leading to SSRF, as demonstrated by an index.php/System/MailConnect/host/127.0.0.1/port/22/secure/ URI.
# This can undermine accountability of where scan or connections actually came from and or bypass
# the FW etc. This can be automated via script or using Web Browser.