PT-2024-6374 · D Link · D-Link Di-8300

Lyaobol

·

Published

2024-09-08

·

Updated

2024-09-13

·

CVE-2024-44411

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DI-8300 version 16.07.26A1
Description The issue is related to the msp info htm function in the D-Link DI-8300 router's firmware, which is vulnerable to command injection. This vulnerability can be exploited by a remote attacker to execute arbitrary commands using a GET request.
Recommendations For D-Link DI-8300 version 16.07.26A1, consider disabling the msp info htm function until a patch is available to prevent command injection attacks. Restrict access to the vulnerable function to minimize the risk of exploitation. Avoid using the msp info htm function in API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2024-07416
CVE-2024-44411

Affected Products

D-Link Di-8300