PT-2023-5871 · D Link · D-Link Dsl-3782
CVE-2023-44959
·
Publicado
2023-02-10
·
Atualizado
2024-09-18
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DSL-3782 versions 1.03 and earlier
Description
The issue allows remote authenticated users to execute arbitrary code as root via the Router IP Address fields of the network settings page. This is related to the lack of protection measures for the web page structure when handling the Router IP Address fields. Exploitation of the issue can allow a remote attacker to execute arbitrary code.
Recommendations
For D-Link DSL-3782 versions 1.03 and earlier, consider disabling access to the network settings page until a patch is available. Restrict access to the Router IP Address fields to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Command Injection
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
D-Link Dsl-3782