PT-2015-3344 · D Link · D-Link Dwr-932B

Pierre Kim

·

Published

2015-12-04

·

Updated

2021-04-23

·

CVE-2016-10182

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DWR-932B router (affected versions not specified)
Description The issue is related to the qmiweb component of the D-Link DWR-932B router's firmware, which lacks input data sanitization measures. This allows a remote attacker to inject commands by adding a ` character, potentially enabling the execution of arbitrary commands.
Recommendations For the D-Link DWR-932B router, consider disabling the qmiweb component until a patch is available to prevent command injection attacks. Restrict access to the qmiweb interface to minimize the risk of exploitation. Avoid using the ` character in input fields for the qmiweb component until the issue is resolved.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02549
CVE-2016-10182

Affected Products

D-Link Dwr-932B