D-Link Remote Administration Arbitrary DHCP Address Release Vulnerability

The DI-804 is a hardware gateway and firewall solution distributed and maintained by D-Link.

It has been reported that a problem with the remote administration interface could allow for the release of DHCP allocated addresses. When remote administration is enabled, insufficient access control is allegedly placed on the /release.html page. This page is used to manipulate DHCP allocated addresses, and could be used to revoke leases on assigned addresses.


 

Privacy Statement
Copyright 2010, SecurityFocus