cbcvebase.
CVE-2021-46379
published 2022-03-04

CVE-2021-46379: DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site.

PriorityP279medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
15.70%
96.5th percentile
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site.

Affected

1 ranges
VendorProductVersion rangeFixed in
dlinkdir-850l_firmware

Detection & IOCsextracted from sources · hover to see the quote

url/boafrm/formWlanRedirect?redirect-url=http://interact.sh&wlan_id=1
path/boafrm/formWlanRedirect
  • Detect open redirect exploitation attempts by monitoring HTTP GET requests to the path /boafrm/formWlanRedirect with a user-supplied redirect-url parameter pointing to an external/untrusted host.
  • The vulnerability requires no authentication (PR:N) and affects D-Link DIR-850L firmware version ET850-1.08TRb03; prioritize detection on internet-exposed D-Link DIR-850 devices running this firmware version.
  • ·The exploit requires only a single unauthenticated GET request; no session or credentials are needed, meaning any network-level access to the device's web interface is sufficient to trigger the redirect.
  • ·The redirect-url parameter is fully attacker-controlled; detection rules should flag any external domain value in this parameter, not just known-bad domains like interact.sh used in the PoC template.

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vulncheck6.1MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.