← Advisories

devolo dLAN 550 duo+ Starter Kit Cross-Site Request Forgery

Medium
Advisory ID
ZSL-2019-5507
Release Date
03 February 2019
Vendor
Affected Version
dLAN 500 AV Wireless+ 3.1.0-1 (i386)
Tested On
Linux 2.6.31
Summary

Devolo dLAN® 550 duo+ Starter Kit is Powerlineadapter which is a cost-effective and helpful networking alternative for any location without structured network wiring. Especially in buildings or residences lacking network cables or where updating the wiring would be expensive and complicated, Powerline adapters provide networking at high transmission rates.

Description

The web application allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. The devolo web application uses predictable URL/form actions in a repeatable way. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.

Proof of Concept
Disclosure Timeline
04.10.2017Vulnerability discovered.
11.10.2017Vendor contacted via email.
14.10.2017No response from the vendor.
15.10.2017Second attempt - Vendor contacted via email.
02.02.2019No response from the vendor.
03.02.2019Public security advisory released.
Credits
Vulnerability discovered by Stefan Petrushevski
References
Changelog
03.02.2019Initial release
10.02.2019Added reference [2], [3], [4] and [5]
23.03.2026Added reference [6]