PT-2023-5871 · D Link · D-Link Dsl-3782

CVE-2023-44959

·

Publicado

2023-02-10

·

Atualizado

2024-09-18

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DSL-3782 versions 1.03 and earlier
Description The issue allows remote authenticated users to execute arbitrary code as root via the Router IP Address fields of the network settings page. This is related to the lack of protection measures for the web page structure when handling the Router IP Address fields. Exploitation of the issue can allow a remote attacker to execute arbitrary code.
Recommendations For D-Link DSL-3782 versions 1.03 and earlier, consider disabling access to the network settings page until a patch is available. Restrict access to the Router IP Address fields to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-06564
CVE-2023-44959

Produtos afetados

D-Link Dsl-3782