PT-2019-8631 · D Link · D-Link Dcs-1130
Mandar Satam
·
Publicado
2019-07-02
·
Atualizado
2023-04-26
·
CVE-2017-8408
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DCS-1130 devices (affected versions not specified)
Description
An issue was discovered on D-Link DCS-1130 devices, where the device provides a user with the capability of setting a SMB folder for the video clippings recorded by the device. The GET parameters passed in this request result in being passed as commands to a "system" API in the function, thus resulting in command injection on the device. The binary "cgibox" contains the vulnerable function "sub 7EAFC" that receives the values sent by the GET request. The value set in GET parameter
user is extracted in function sub 7E49C which is then passed to the vulnerable system API call.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
D-Link Dcs-1130