Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qvj8-qcrx-49c6

Опубликовано: 22 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary operating system commands through well-designed /HNAP1 requests. Before the HNAP API function can process the request, the system function executes an untrusted command that triggers the vulnerability.

A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary operating system commands through well-designed /HNAP1 requests. Before the HNAP API function can process the request, the system function executes an untrusted command that triggers the vulnerability.

EPSS

Процентиль: 95%
0.19783
Средний

9.8 Critical

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 9.8
nvd
около 3 лет назад

A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary operating system commands through well-designed /HNAP1 requests. Before the HNAP API function can process the request, the system function executes an untrusted command that triggers the vulnerability.

CVSS3: 9.8
fstec
больше 3 лет назад

Уязвимость микропрограммного обеспечения маршрутизаторов D–Link DIR-823G, существующая из-за непринятия мер по нейтрализации специальных элементов, используемых в команде операционной системы, позволяющая нарушителю выполнить произвольные команды операционной системы

EPSS

Процентиль: 95%
0.19783
Средний

9.8 Critical

CVSS3

Дефекты

CWE-78