D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a command injection vulnerability via the ST parameter in the lxmldbc_system() function.
References
Link | Resource |
---|---|
https://github.com/naihsin/IoT/blob/main/D-Link/DIR-600/cmd%20injection/README.md | Exploit Third Party Advisory |
https://github.com/naihsin/IoT/tree/main/D-Link/DIR-600/cmd%20injection | Exploit Third Party Advisory |
https://hackmd.io/%40naihsin/By2datZD2 | |
https://www.dlink.com/en/security-bulletin/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2023-06-12 20:15
Updated : 2023-11-07 04:15
NVD link : CVE-2023-33625
Mitre link : CVE-2023-33625
CVE.ORG link : CVE-2023-33625
JSON object : View
Products Affected
dlink
- dir-600_firmware
- dir-600
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')