ID

VAR-200406-0054


CVE

CAN-2004-0615


TITLE

CNVD-2004-1751

Trust: 0.6

sources: CNVD: CNVD-2004-1751

DESCRIPTION

The D-Link DI-614 + SOHO router running in firmware 2.30 and the DI-704 SOHO router running in firmware 2.60B2 have vulnerabilities that could allow remote attackers to inject arbitrary scripts or HTML programs using the DHCP HOSTNAM option requested by DHCP. It is reported that the DI-614+, DI-704, and the DI-624 are susceptible to an HTML injection vulnerability in their DHCP log. An attacker who has access to the wireless, or internal network segments of the router can craft malicious DHCP hostnames, that when sent to the router, will be logged for later viewing by the administrator of the device. The injected HTML can be used to cause the administrator to make unintended changes to the configuration of the router. Other attacks may be possible. Although only the DI-614+, DI-704, and the DI-624 are reported vulnerable, code reuse across devices is common and other products may also be affected

Trust: 0.81

sources: CNVD: CNVD-2004-1751 // BID: 10587

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2004-1751

AFFECTED PRODUCTS

vendor:nonemodel: - scope: - version: -

Trust: 0.6

vendor:d linkmodel:dl-704 b2scope:eqversion:2.60

Trust: 0.3

vendor:d linkmodel:dl-704 b6scope:eqversion:2.56

Trust: 0.3

vendor:d linkmodel:dl-704 b5scope:eqversion:2.56

Trust: 0.3

vendor:d linkmodel:di-624 soho routerscope:eqversion:1.28

Trust: 0.3

vendor:d linkmodel:di-614+scope:eqversion:2.18

Trust: 0.3

vendor:d linkmodel:di-614+scope:eqversion:2.10

Trust: 0.3

vendor:d linkmodel:di-614+ fscope:eqversion:2.0

Trust: 0.3

vendor:d linkmodel:di-614+ 3gscope:eqversion:2.0

Trust: 0.3

vendor:d linkmodel:di-614+scope:eqversion:2.03

Trust: 0.3

vendor:d linkmodel:di-614+scope:eqversion:2.0

Trust: 0.3

sources: CNVD: CNVD-2004-1751 // BID: 10587

THREAT TYPE

network

Trust: 0.3

sources: BID: 10587

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 10587

EXTERNAL IDS

db:BIDid:10587

Trust: 0.9

db:CNCVEid:CNCVE-20040615

Trust: 0.6

db:XFid:16468

Trust: 0.6

db:NVDid:CAN-2004-0615

Trust: 0.6

db:CNVDid:CNVD-2004-1751

Trust: 0.6

sources: CNVD: CNVD-2004-1751 // BID: 10587

REFERENCES

url:http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=can-2004-0615

Trust: 0.6

url:http://www.securityfocus.com/bid/10587/solution/

Trust: 0.6

url:http://xforce.iss.net/xforce/xfdb/16468

Trust: 0.6

url:http://www.d-link.com/

Trust: 0.3

url:/archive/1/366615

Trust: 0.3

url:/archive/1/367855

Trust: 0.3

url:/archive/1/366826

Trust: 0.3

sources: CNVD: CNVD-2004-1751 // BID: 10587

CREDITS

c3rb3r <c3rb3r@sympatico.ca> originally disclosed this vulnerability.

Trust: 0.3

sources: BID: 10587

SOURCES

db:CNVDid:CNVD-2004-1751
db:BIDid:10587

LAST UPDATE DATE

2022-05-04T09:53:06.084000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2004-1751date:2004-06-21T00:00:00
db:BIDid:10587date:2004-06-21T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2004-1751date:2004-06-21T00:00:00
db:BIDid:10587date:2004-06-21T00:00:00