PT-2023-9459 · D Link · D-Link Dar-7000

Shechenran

·

Published

2023-09-22

·

Updated

2024-09-23

·

CVE-2024-9004

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DAR-7000 up to 20240912
Description A critical vulnerability has been found in the file /view/DBManage/Backup Server commit.php, allowing for os command injection through the manipulation of the host argument. This issue can be exploited remotely. The vulnerability exists due to the lack of measures to neutralize special elements used in the operating system command. It is possible for an attacker to execute arbitrary commands remotely.
Recommendations For D-Link DAR-7000 up to 20240912, as the products are no longer supported by the maintainer, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the /view/DBManage/Backup Server commit.php file and avoiding the use of the host argument in this context until further guidance is available.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-07790
CVE-2024-9004

Affected Products

D-Link Dar-7000