PT-2024-6372 · D Link · D-Link Di-8300

Lyaobol

·

Published

2024-09-04

·

Updated

2024-09-13

·

CVE-2024-44410

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DI-8300 version 16.07.26A1
Description The issue is related to the upgrade filter asp function in the D-Link DI-8300 router's firmware, which does not properly sanitize input data. This can be exploited by a remote attacker to execute arbitrary commands using a GET request. The vulnerability allows for command injection, potentially leading to unauthorized access and control of the device.
Recommendations For D-Link DI-8300 version 16.07.26A1, consider disabling the upgrade filter asp function until a patch is available to prevent command injection attacks. Restrict access to the device and its management interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-07414
CVE-2024-44410

Affected Products

D-Link Di-8300