PT-2019-2519 · D Link · D-Link Dsl-3782
Lorenzo Comi
·
Publicado
2019-04-01
·
Atualizado
2019-04-02
·
CVE-2018-17990
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DSL-3782 version 1.01
Description
The issue is related to insufficient argument validation in the Acl.asp component of the D-Link DSL-3782 router's microprogram, which can be exploited by a remote attacker to execute arbitrary commands using the
ScrIPaddrEndTXT parameter. This can allow the attacker to perform unauthorized actions.Recommendations
For version 1.01, consider restricting access to the Acl.asp component until a patch is available. As a temporary workaround, avoid using the
ScrIPaddrEndTXT parameter in the affected CLI commands to minimize the risk of exploitation.Exploit
Correção
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
D-Link Dsl-3782