Overview

Affected version

DIR-618 Bx 2.02

Vulnerability details

An improper access control vulnerability exists in the web management interface of DIR-618 Bx 2.02. By sending a specially crafted unauthenticated HTTP POST request to the goform endpoint with the header set to formSetDomainFilter, an attacker can set the parent control service of the device.

POC