# Exploit Title: Multiple D-Link Router Authentication Bypass Vulnerabilities
# Date: 12-01-2011
# Author: Craig Heffner, /dev/ttyS0
# Firmware Link: [Enlace externo eliminado para invitados]
# Firmware Version(s): All
# Tested on: DIR-300, DIR-320, DIR-615 revD
Multiple D-Link routers that use a PHP based Web interface suffer from the same authentication bypass
vulnerability which allows unprivileged users to view and modify administrative router settings.
Further, even if remote administration is disabled this vulnerability can be exploited by a remote
attacker via a CSRF attack.
The vulnerability has been confirmed in the following routers:
DIR-615 revD
DIR-320
DIR-300
The following example URL will allow access to the router's main administrative Web page without authentication:
http:// 192.168.0.1/bsc_lan.php?NO_NEED_ ... TH_GROUP=0 (hay un espacio entre http:// y 192. Lo puse para que se vea la url entera)
For a more detailed description of the vulnerability, see: [Enlace externo eliminado para invitados] ... bility.pdf.
Note that this vulnerability was independently discovered in the DIR-300 and subsequently reported by Karol Celin on 09-Nov-2010 [1].
[1] [Enlace externo eliminado para invitados] ... 0/threaded
Fuente: exploit-db
Un saludo