CVE-2012-5319

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
08/10/2012
Last modified:
11/04/2025

Description

Cross-site request forgery (CSRF) vulnerability in setup/security.cgi in D-Link DCS-900, DCS-2000, and DCS-5300 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the rootpass parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:dlink:dcs-2000:-:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-5300:-:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dcs-900:-:*:*:*:*:*:*:*