PT-2025-31993 · D Link · Dir-300 Rev B+1
Published
2012-12-14
·
Updated
2025-08-05
·
CVE-2013-10069
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link routers versions prior to 2.14b01 (DIR-600 rev B)
D-Link routers versions prior to 2.13 (DIR-300 rev B)
Description
The web interface of multiple D-Link routers contains an unauthenticated operating system command injection vulnerability in the
command.php file. This file improperly handles the cmd POST parameter. A remote attacker can exploit this flaw without authentication to generate a Telnet service on a specified port, enabling persistent interactive shell access as root.Recommendations
For D-Link routers version prior to 2.14b01 (DIR-600 rev B), update to version 2.14b01 or later.
For D-Link routers version prior to 2.13 (DIR-300 rev B), update to version 2.13 or later.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dir-300 Rev B
Dir-600 Rev B