PT-2023-3645 · D Link · D-Link Dsl-G256Dg+1

Nerya Zadkani

·

Published

2023-06-14

·

Updated

2024-11-27

·

CVE-2023-32223

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DSL-224 version 3.0.10 D-Link DSL-G256DG (affected versions not specified)
Description The issue is related to a command execution vulnerability that can be exploited after authentication. It is associated with deficiencies in the authentication procedure, allowing a remote attacker to execute arbitrary commands.
Recommendations For D-Link DSL-224 version 3.0.10, update to a newer version that contains a fix for this issue. For D-Link DSL-G256DG, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Origin Validation Error

Weakness Enumeration

Related Identifiers

BDU:2023-03929
CVE-2023-32223

Affected Products

D-Link Dsl-224
D-Link Dsl-G256Dg