PT-2015-3344 · D Link · D-Link Dwr-932B
Pierre Kim
·
Publicado
2015-12-04
·
Atualizado
2021-04-23
·
CVE-2016-10182
CVSS v3.1
10
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
D-Link DWR-932B router (affected versions not specified)
Description
The issue is related to the qmiweb component of the D-Link DWR-932B router's firmware, which lacks input data sanitization measures. This allows a remote attacker to inject commands by adding a ` character, potentially enabling the execution of arbitrary commands.
Recommendations
For the D-Link DWR-932B router, consider disabling the qmiweb component until a patch is available to prevent command injection attacks.
Restrict access to the qmiweb interface to minimize the risk of exploitation.
Avoid using the ` character in input fields for the qmiweb component until the issue is resolved.
Exploit
Correção
Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
D-Link Dwr-932B