PT-2020-7534 · D Link · Dsr-250N+6

0_O

·

Published

2020-02-11

·

Updated

2021-04-23

·

CVE-2013-5945

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: D-Link DSR-150 versions prior to 1.08B44 D-Link DSR-150N versions prior to 1.05B64 D-Link DSR-250 versions prior to 1.08B44 D-Link DSR-250N versions prior to 1.08B44 D-Link DSR-500 versions prior to 1.08B77 D-Link DSR-500N versions prior to 1.08B77 D-Link DSR-1000 versions prior to 1.08B77 D-Link DSR-1000N versions prior to 1.08B77
Description: The issue allows remote attackers to execute arbitrary SQL commands via the password to the login.authenticate function in share/lua/5.1/teamf1lualib/login.lua or captivePortal.lua. This can be exploited by sending a specially crafted password.
Recommendations: For D-Link DSR-150, update to firmware version 1.08B44 or later. For D-Link DSR-150N, update to firmware version 1.05B64 or later. For D-Link DSR-250, update to firmware version 1.08B44 or later. For D-Link DSR-250N, update to firmware version 1.08B44 or later. For D-Link DSR-500, update to firmware version 1.08B77 or later. For D-Link DSR-500N, update to firmware version 1.08B77 or later. For D-Link DSR-1000, update to firmware version 1.08B77 or later. For D-Link DSR-1000N, update to firmware version 1.08B77 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-5945

Affected Products

Dsr-1000
Dsr-1000N
Dsr-150
Dsr-250
Dsr-250N
Dsr-500
Dsr-500N