Cross-Site Scripting and Information Disclosure Vulnerability in D-Link DCS-1130
CVE-2017-8406
8.8HIGH
What is CVE-2017-8406?
A security issue has been identified in D-Link DCS-1130 devices, where the device exposes a crossdomain.xml file without access restrictions. This vulnerability allows any hosted flash file from any domain to interact with the device's webserver, potentially leaking sensitive user information, including credentials stored in clear text. Additionally, the lack of a cross-site request forgery (CSRF) protection mechanism enables attackers to manipulate logged-in users, executing unauthorized actions on the web management interface. This can lead to credential theft from the device's responses, significantly compromising user security.