CVE-2017-7404 describes a Cross-Site Request Forgery (CSRF) vulnerability affecting the D-Link DIR-615 router before v20.12PTb04. An attacker can leverage this flaw by tricking a logged-in user into visiting a malicious website, which then sends unauthorized requests to the router's web interface. This can lead to a Denial of Service (DoS) by forcing a reboot/crash or, more critically, allow for the upload of malicious firmware. The vulnerability has a CVSS v3.1 score of 8.8 (High), indicating a critical risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. It requires user interaction (UI:R) but no prior authentication (PR:N). Currently, there is no public exploit code available in Metasploit, Nuclei, or ExploitDB, and it is not listed in the CISA KEV catalog. Community discussion and media coverage for this CVE are minimal, suggesting it is not widely known or actively exploited in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 20.12ptb01CPE matchmatch criteria | cpe:2.3:o:dlink:dir-615:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.