PT-2025-31685 · D Link · D-Link Dir-300 Rev B+1
Published
2012-12-14
·
Updated
2025-08-01
·
CVE-2013-10048
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-300 rev B versions prior to firmware 2.14b01
D-Link DIR-600 versions prior to firmware 2.14b01
D-Link DIR-600 versions prior to firmware 2.13
Description
An OS command injection vulnerability exists in various legacy D-Link routers due to improper input handling. A remote attacker can execute arbitrary shell commands with root privileges by sending specially crafted POST requests to the
/command.php endpoint. This allows for full device takeover, including launching services such as Telnet, exfiltrating credentials, modifying system configuration, and disrupting availability. The vulnerability stems from a lack of authentication and inadequate sanitation of the cmd parameter.Recommendations
Update D-Link DIR-300 rev B to firmware version 2.14b01 or later.
Update D-Link DIR-600 to firmware version 2.14b01 or later.
Update D-Link DIR-600 to firmware version 2.13 or later.
Exploit
Fix
Improper Privilege Management
Incorrect Privilege Assignment
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dir-300 Rev B
D-Link Dir-600