CVE-2021-46379
published 2022-03-04CVE-2021-46379: DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site.
PriorityP279medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
15.70%
96.5th percentile
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlink | dir-850l_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect open redirect exploitation attempts by monitoring HTTP GET requests to the path /boafrm/formWlanRedirect with a user-supplied redirect-url parameter pointing to an external/untrusted host. ↗
- →The vulnerability requires no authentication (PR:N) and affects D-Link DIR-850L firmware version ET850-1.08TRb03; prioritize detection on internet-exposed D-Link DIR-850 devices running this firmware version. ↗
- ·The exploit requires only a single unauthenticated GET request; no session or credentials are needed, meaning any network-level access to the device's web interface is sufficient to trigger the redirect. ↗
- ·The redirect-url parameter is fully attacker-controlled; detection rules should flag any external domain value in this parameter, not just known-bad domains like interact.sh used in the PoC template. ↗
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vulncheck6.1MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-276x-qw7f-57vq: DLink DIR850 ET850-1
ghsa_unreviewed·2022-03-05
CVE-2021-46379 [MEDIUM] CWE-601 GHSA-276x-qw7f-57vq: DLink DIR850 ET850-1
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site.
VulnCheck
D-Link dir-850l_firmware URL Redirection to Untrusted Site ('Open Redirect')
vulncheck·2021·CVSS 6.1
CVE-2021-46379 [MEDIUM] D-Link dir-850l_firmware URL Redirection to Untrusted Site ('Open Redirect')
D-Link dir-850l_firmware URL Redirection to Untrusted Site ('Open Redirect')
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site.
Affected: D-Link dir-850l_firmware
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2024-01-22&host_type=src&vulnerability=cve-2021-46379; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2024-01-24&host_type=src&vulnerability=cve-2021-46379; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2024-01-27&host_type=src&vulne
No detection rules found.
Exploit-DB
DLINK DIR850 - Open Redirect
exploitdb·2022-05-11·CVSS 6.1
CVE-2021-46379 [MEDIUM] DLINK DIR850 - Open Redirect
DLINK DIR850 - Open Redirect
---
# Exploit Title: DLINK DIR850 - Open Redirect
# Product: Dlink
# Model: DIR850
# Date: 14/1/2022
# CVE: CVE-2021-46379
# Exploit Author: AhmedAlroky
# Hardware version: b1
# Firmware version: ET850-1.08TRb03
# Vendor home page: https://www.dlink.com/
#Exploit :
Visit http:///boafrm/formWlanRedirect?redirect-url=http://attacker.com&wlan_id=1
Nuclei
D-Link DIR850 ET850-1.08TRb03 - Open Redirect
nuclei·CVSS 6.1
CVE-2021-46379 [MEDIUM] D-Link DIR850 ET850-1.08TRb03 - Open Redirect
D-Link DIR850 ET850-1.08TRb03 - Open Redirect
DLink DIR850 ET850-1.08TRb03 contains incorrect access control vulnerability in URL redirection, which can be used to mislead users to go to untrusted sites.
Template:
id: CVE-2021-46379
info:
name: D-Link DIR850 ET850-1.08TRb03 - Open Redirect
author: 0x_Akoko
severity: medium
description: DLink DIR850 ET850-1.08TRb03 contains incorrect access control vulnerability in URL redirection, which can be used to mislead users to go to untrusted sites.
impact: |
An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the download of malware.
remediation: |
Apply the latest firmware update provided by D-Link to fix the open redirect vulnerability.
reference:
- https://nvd.nist.gov/vuln/deta
http://packetstormsecurity.com/files/167041/DLINK-DIR850-Open-Redirection.htmlhttps://drive.google.com/file/d/1rrlwnIxSHEoO4SMAHRPKZSRzK5MwZQRf/view?usp=sharinghttps://www.dlink.com/en/security-bulletin/http://packetstormsecurity.com/files/167041/DLINK-DIR850-Open-Redirection.htmlhttps://drive.google.com/file/d/1rrlwnIxSHEoO4SMAHRPKZSRzK5MwZQRf/view?usp=sharinghttps://www.dlink.com/en/security-bulletin/
2022-03-04
Published
Exploited in the wild