CVE-2017-5633 EXPLOIT
8.0
HIGH · CVSS 3.0 · EPSS 4% (pctl 90)
Patch early
A public exploit exists.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities on the D-Link DI-524 Wireless Router with firmware 9.01 allow remote attackers to (1) change the admin password, (2) reboot the device, or (3) possibly have unspecified other impact via crafted requests to CGI programs.
Scoring
| CVSS | 8.0 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 3.96% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-352 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-03-06 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| d-link | di-524 firmware |
| dlink | di-524 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | D-Link DI-524 - Cross-Site Request Forgery | 2016-12-09 |
References
→ the Explorer · watch your stack · NVD