peter bassill · operator
$ cve CVE-2017-5633 JSON

CVE-2017-5633 EXPLOIT

8.0
HIGH · CVSS 3.0 · EPSS 4% (pctl 90)

Patch early

A public exploit exists.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities on the D-Link DI-524 Wireless Router with firmware 9.01 allow remote attackers to (1) change the admin password, (2) reboot the device, or (3) possibly have unspecified other impact via crafted requests to CGI programs.

Scoring

CVSS8.0 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS3.96% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2017-03-06
Last modified2026-06-17

Affected (2)

VendorProduct
d-linkdi-524 firmware
dlinkdi-524

Public exploits

SourceTitleDate
exploit-dbD-Link DI-524 - Cross-Site Request Forgery2016-12-09

References

→ the Explorer  ·  watch your stack  ·  NVD