PT-2020-6764 · D Link · D-Link Dir-823G
Published
2020-09-14
·
Updated
2021-11-05
·
CVE-2020-25367
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-823G version V1.0.2B05
Description
A command injection vulnerability was discovered in the HNAP1 protocol. An attacker can execute arbitrary web scripts via shell metacharacters in the
Captcha field to Login. This issue is related to insufficient argument checking in the protocol implementation, allowing a remote attacker to execute arbitrary commands by introducing specially crafted metacharacters.Recommendations
For D-Link DIR-823G version V1.0.2B05, consider disabling the Captcha field for Login until a patch is available to prevent exploitation. Restrict access to the HNAP1 protocol to minimize the risk of command injection attacks. Avoid using the
Captcha field in the Login process until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D-Link Dir-823G