Vulnerabilities (CVE)

Filtered by vendor D-link Subscribe
Filtered by product Central Wifimanager
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-15517 1 D-link 1 Central Wifimanager 2019-02-21 5.0 MEDIUM 8.6 HIGH
The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually allows outbound TCP to any port on any IP address, leading to SSRF, as demonstrated by an index.php/System/MailConnect/host/127.0.0.1/port/22/secure/ URI.
CVE-2018-17442 1 D-link 1 Central Wifimanager 2018-11-23 6.5 MEDIUM 8.8 HIGH
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. An unrestricted file upload vulnerability in the onUploadLogPic endpoint allows remote authenticated users to execute arbitrary PHP code.