PT-2025-31693 · D Link · Dlink Router
Published
2012-11-11
·
Updated
2025-09-23
·
CVE-2013-10059
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link routers version 8.04
Description
An authenticated OS command injection vulnerability exists via the
tools vct.htm endpoint. The web interface fails to sanitize input passed from the ping ipaddr parameter to the tools vct.htm diagnostic interface, allowing attackers to inject arbitrary shell commands using backtick encapsulation. With default credentials, an attacker can exploit this blind injection vector to execute arbitrary commands.Recommendations
For version 8.04, ensure proper input sanitization is implemented for the
ping ipaddr parameter within the tools vct.htm endpoint to prevent command injection. As a temporary workaround, restrict access to the tools vct.htm interface.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dlink Router