PT-2025-31685 · D Link · D-Link Dir-300 Rev B+1

CVE-2013-10048

·

Published

2012-12-14

·

Updated

2025-08-01

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DIR-300 rev B versions prior to firmware 2.14b01 D-Link DIR-600 versions prior to firmware 2.14b01 D-Link DIR-600 versions prior to firmware 2.13
Description An OS command injection vulnerability exists in various legacy D-Link routers due to improper input handling. A remote attacker can execute arbitrary shell commands with root privileges by sending specially crafted POST requests to the /command.php endpoint. This allows for full device takeover, including launching services such as Telnet, exfiltrating credentials, modifying system configuration, and disrupting availability. The vulnerability stems from a lack of authentication and inadequate sanitation of the cmd parameter.
Recommendations Update D-Link DIR-300 rev B to firmware version 2.14b01 or later. Update D-Link DIR-600 to firmware version 2.14b01 or later. Update D-Link DIR-600 to firmware version 2.13 or later.

Exploit

Fix

Improper Privilege Management

Incorrect Privilege Assignment

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-09358
CVE-2013-10048

Affected Products

D-Link Dir-300 Rev B
D-Link Dir-600