PT-2024-8244 · D Link · D-Link Dir-823G

Published

2024-11-05

·

Updated

2024-11-05

·

CVE-2024-51023

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: D-Link DIR 823G version 1.0.2B05
Description: The issue is related to a command injection vulnerability in the SetNetworkTomographySettings function, specifically via the Address parameter. This allows attackers to execute arbitrary OS commands by sending a crafted request. The vulnerability is due to the lack of proper neutralization of special elements used in the operating system command when processing the Address parameter.
Recommendations: For D-Link DIR 823G version 1.0.2B05, as a temporary workaround, consider disabling the SetNetworkTomographySettings function until a patch is available. Restrict access to the Address parameter in the affected function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-09797
CVE-2024-51023

Affected Products

D-Link Dir-823G