DIR-605L C1 3.02
An improper access control vulnerability exists in the web management interface of DIR-605L C1 3.02. By sending a specially crafted unauthenticated HTTP POST request to the goform
endpoint with the header set to formAdvFirewall
, an attacker can set the firewall and DMZ service of the device.