Research Article

RW-Fuzzer: A Fuzzing Method for Vulnerability Mining on Router Web Interface

Table 1

Common router Web vulnerabilities.

Device nameCWE (list of common defects)Describe

D-Link/DIR-300CWE-352Cross-site request forgery
NetgearCWE-601URL redirects to untrusted site
D-Link DIR-600/300CWE-200Information leakage
D-Link 850LCWE-319Sensitive information transmitted in clear text
D-Link/DIR8xxCWE-295Improper certificate validation
Billion 7700NR4CWE-798Use hardcoded certificates
Link 850LCWE-798Use hardcoded certificates
TOTOLINKCWE-20Improper certificate validation
TP-LinkCWE-284Improper access control