ID
VAR-200406-0054
CVE
CAN-2004-0615
TITLE
CNVD-2004-1751
Trust: 0.6
DESCRIPTION
The D-Link DI-614 + SOHO router running in firmware 2.30 and the DI-704 SOHO router running in firmware 2.60B2 have vulnerabilities that could allow remote attackers to inject arbitrary scripts or HTML programs using the DHCP HOSTNAM option requested by DHCP. It is reported that the DI-614+, DI-704, and the DI-624 are susceptible to an HTML injection vulnerability in their DHCP log. An attacker who has access to the wireless, or internal network segments of the router can craft malicious DHCP hostnames, that when sent to the router, will be logged for later viewing by the administrator of the device. The injected HTML can be used to cause the administrator to make unintended changes to the configuration of the router. Other attacks may be possible. Although only the DI-614+, DI-704, and the DI-624 are reported vulnerable, code reuse across devices is common and other products may also be affected
Trust: 0.81
IOT TAXONOMY
category: | ['IoT'] | sub_category: | - | Trust: 0.6 |
AFFECTED PRODUCTS
vendor: | none | model: | - | scope: | - | version: | - | Trust: 0.6 |
vendor: | d link | model: | dl-704 b2 | scope: | eq | version: | 2.60 | Trust: 0.3 |
vendor: | d link | model: | dl-704 b6 | scope: | eq | version: | 2.56 | Trust: 0.3 |
vendor: | d link | model: | dl-704 b5 | scope: | eq | version: | 2.56 | Trust: 0.3 |
vendor: | d link | model: | di-624 soho router | scope: | eq | version: | 1.28 | Trust: 0.3 |
vendor: | d link | model: | di-614+ | scope: | eq | version: | 2.18 | Trust: 0.3 |
vendor: | d link | model: | di-614+ | scope: | eq | version: | 2.10 | Trust: 0.3 |
vendor: | d link | model: | di-614+ f | scope: | eq | version: | 2.0 | Trust: 0.3 |
vendor: | d link | model: | di-614+ 3g | scope: | eq | version: | 2.0 | Trust: 0.3 |
vendor: | d link | model: | di-614+ | scope: | eq | version: | 2.03 | Trust: 0.3 |
vendor: | d link | model: | di-614+ | scope: | eq | version: | 2.0 | Trust: 0.3 |
THREAT TYPE
network
Trust: 0.3
TYPE
Input Validation Error
Trust: 0.3
EXTERNAL IDS
db: | BID | id: | 10587 | Trust: 0.9 |
db: | CNCVE | id: | CNCVE-20040615 | Trust: 0.6 |
db: | XF | id: | 16468 | Trust: 0.6 |
db: | NVD | id: | CAN-2004-0615 | Trust: 0.6 |
db: | CNVD | id: | CNVD-2004-1751 | Trust: 0.6 |
REFERENCES
url: | http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=can-2004-0615 | Trust: 0.6 |
url: | http://www.securityfocus.com/bid/10587/solution/ | Trust: 0.6 |
url: | http://xforce.iss.net/xforce/xfdb/16468 | Trust: 0.6 |
url: | http://www.d-link.com/ | Trust: 0.3 |
url: | /archive/1/366615 | Trust: 0.3 |
url: | /archive/1/367855 | Trust: 0.3 |
url: | /archive/1/366826 | Trust: 0.3 |
CREDITS
c3rb3r <c3rb3r@sympatico.ca> originally disclosed this vulnerability.
Trust: 0.3
SOURCES
db: | CNVD | id: | CNVD-2004-1751 |
db: | BID | id: | 10587 |
LAST UPDATE DATE
2022-05-04T09:53:06.084000+00:00
SOURCES UPDATE DATE
db: | CNVD | id: | CNVD-2004-1751 | date: | 2004-06-21T00:00:00 |
db: | BID | id: | 10587 | date: | 2004-06-21T00:00:00 |
SOURCES RELEASE DATE
db: | CNVD | id: | CNVD-2004-1751 | date: | 2004-06-21T00:00:00 |
db: | BID | id: | 10587 | date: | 2004-06-21T00:00:00 |