PT-2025-31685 · D Link · D-Link Dir-300 Rev B+1

Published

2012-12-14

·

Updated

2025-08-01

·

CVE-2013-10048

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DIR-300 rev B versions prior to firmware 2.14b01 D-Link DIR-600 versions prior to firmware 2.14b01 D-Link DIR-600 versions prior to firmware 2.13
Description An OS command injection vulnerability exists in various legacy D-Link routers due to improper input handling. A remote attacker can execute arbitrary shell commands with root privileges by sending specially crafted POST requests to the /command.php endpoint. This allows for full device takeover, including launching services such as Telnet, exfiltrating credentials, modifying system configuration, and disrupting availability. The vulnerability stems from a lack of authentication and inadequate sanitation of the cmd parameter.
Recommendations Update D-Link DIR-300 rev B to firmware version 2.14b01 or later. Update D-Link DIR-600 to firmware version 2.14b01 or later. Update D-Link DIR-600 to firmware version 2.13 or later.

Exploit

Fix

Improper Privilege Management

Incorrect Privilege Assignment

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-09358
CVE-2013-10048

Affected Products

D-Link Dir-300 Rev B
D-Link Dir-600