Description
This module exploits a SQLi vulnerability found in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6. The vulnerability is an exposed API endpoint that allows the execution of SQL queries without authentication, using this vulnerability, it's possible to retrieve usernames and password hashes of registered users, device configuration, and other data, it's also possible to add users, or edit database information.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use auxiliary/sqli/dlink/dlink/central_wifimanager_sqlimsf undefined(central_wifimanager_sqli) > show actions ...actions...msf undefined(central_wifimanager_sqli) > set ACTION < action-name >msf undefined(central_wifimanager_sqli) > show options ...show and set options...msf undefined(central_wifimanager_sqli) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub