CVE-2020-13786
Description
D-Link DIR-865L Ax 1.20B01 Beta devices allow CSRF.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
D-Link DIR-865L Ax routers running firmware 1.20B01 Beta are vulnerable to CSRF, enabling unauthorized actions by tricking an authenticated admin.
Vulnerability
D-Link DIR-865L hardware revision Ax running firmware version 1.20B01 Beta (released August 9, 2018) is vulnerable to Cross-Site Request Forgery (CSRF) [1][2]. The web interface does not properly validate or require a unique token for state-changing requests, allowing an attacker to forge requests on behalf of an authenticated administrator.
Exploitation
An attacker can craft a malicious HTML page or link that, when visited by an authenticated administrator, sends a forged request to the router's web interface [1]. No special network position is required; the attacker only needs to trick the victim into visiting a malicious site while logged into the router. The forged request can perform any action the administrator is authorized to do, such as changing settings or initiating file operations.
Impact
Successful CSRF exploitation allows an attacker to perform arbitrary actions on the router with administrative privileges, including modifying configuration, uploading malicious files, or deleting data [1]. This can lead to full compromise of the router and potential further network attacks. The CSRF vulnerability can be chained with other vulnerabilities (e.g., command injection, cleartext storage) to escalate impact [1].
Mitigation
D-Link has released a beta patch (available at the D-Link support announcement [2]), but the DIR-865L reached End of Support/End of Life on February 1, 2016 [2]. Users are strongly recommended to install the beta patch or upgrade to a supported router model. No other workarounds are documented [1][2].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- D-Link/DIR-865Ldescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- supportannouncement.us.dlink.com/announcement/publication.aspxmitrex_refsource_MISC
- unit42.paloaltonetworks.com/6-new-d-link-vulnerabilities-found-on-home-routers/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.