D-Link Central WiFi Manager CWM(100) Remote Code Execution
Posted by deepcore on August 19, 2020 – 5:53 am
This Metasploit module exploits a PHP code injection vulnerability in D-Link Central WiFi Manager CWM(100) versions below v1.03R0100_BETA6. The vulnerability exists in the username cookie, which is passed to eval() without being sanitized. Dangerous functions are not disabled by default, which makes it possible to get code execution on the target.
Post a reply
You must be logged in to post a comment.