Overview

Affected version

DIR823G_V1.0.2B05_20181207

Vulnerability details

An improper access control vulnerability exists in the web management interface of DIR823G_V1.0.2B05_20181207. By sending a specially crafted unauthenticated HTTP POST request to the /HNAP1/ endpoint with the SOAPAction header set to SetDDNSSettings, an attacker can enable or disable the DDNS service of the device.

POC