Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-3095


Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR865L router (Rev. A1) with firmware before 1.05b07 allow remote attackers to hijack the authentication of administrators for requests that (1) change the administrator password or (2) enable remote management via a request to hedwig.cgi or (3) activate configuration changes via a request to pigwidgeon.cgi.


Published

2013-11-20T13:19:38.913

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-352

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System dlink dir865l_firmware ≤ 1.05 Yes
Operating System dlink dir865l_firmware 1.00b24 Yes
Operating System dlink dir865l_firmware 1.02 Yes
Operating System dlink dir865l_firmware 1.03 Yes
Hardware dlink dir865l - Yes

References