PT-2020-7534 · D Link · Dsr-250N+6
0_O
·
Published
2020-02-11
·
Updated
2021-04-23
·
CVE-2013-5945
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
D-Link DSR-150 versions prior to 1.08B44
D-Link DSR-150N versions prior to 1.05B64
D-Link DSR-250 versions prior to 1.08B44
D-Link DSR-250N versions prior to 1.08B44
D-Link DSR-500 versions prior to 1.08B77
D-Link DSR-500N versions prior to 1.08B77
D-Link DSR-1000 versions prior to 1.08B77
D-Link DSR-1000N versions prior to 1.08B77
Description:
The issue allows remote attackers to execute arbitrary SQL commands via the password to the
login.authenticate function in share/lua/5.1/teamf1lualib/login.lua or captivePortal.lua. This can be exploited by sending a specially crafted password.Recommendations:
For D-Link DSR-150, update to firmware version 1.08B44 or later.
For D-Link DSR-150N, update to firmware version 1.05B64 or later.
For D-Link DSR-250, update to firmware version 1.08B44 or later.
For D-Link DSR-250N, update to firmware version 1.08B44 or later.
For D-Link DSR-500, update to firmware version 1.08B77 or later.
For D-Link DSR-500N, update to firmware version 1.08B77 or later.
For D-Link DSR-1000, update to firmware version 1.08B77 or later.
For D-Link DSR-1000N, update to firmware version 1.08B77 or later.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dsr-1000
Dsr-1000N
Dsr-150
Dsr-250
Dsr-250N
Dsr-500
Dsr-500N