CVE-2013-10069
The web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an unauthenticated OS command injection vulnerability in command.php, which improperly handles the cmd POST parameter.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.9%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an unauthenticated OS command injection vulnerability in command.php, which improperly handles the cmd POST parameter. A remote attacker can exploit this flaw without authentication to spawn a Telnet service on a specified port, enabling persistent interactive shell access as root.
- CVSS 4.0
- 10.0 CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 11.86% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- dlink/dir-600 firmware · dlink/dir-300 firmware
- Source
- disclosure@vulncheck.com
References
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/auxiliary/admin/http/dlink_dir_300_600_exec_noauth.rbExploit
- https://web.archive.org/web/20150428184723/http://www.s3cur1ty.de/m1adv2013-003Exploit, Third Party Advisory
- https://www.exploit-db.com/exploits/24453Exploit
- https://www.vulncheck.com/advisories/dlink-devices-unauth-rceThird Party Advisory
- https://www.exploit-db.com/exploits/24453Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.