ID

VAR-201304-0461


TITLE

D-Link Multiple Product Command Injection Vulnerabilities

Trust: 0.6

sources: CNVD: CNVD-2013-02859

DESCRIPTION

There is a command injection vulnerability in D-Link's various router devices. DIR-600 / DIR-300 revB / DIR-815 / DIR-645 / DIR-412 / DIR-456 / DIR-110 devices fail to properly verify dst parameter data and lack of verification of the session, allowing remote attackers to exploit The vulnerability is injected and executed by any shell command. DIR-600 / DIR-300 revB / DIR-815 / DIR-645 / DIR-412 / DIR-456 / DIR-110 devices fail to properly restrict access to version.txt or DevInfo, allowing remote attackers to submit requests directly Model name, hardware version, kernel version, firmware version, MAC address information. D-Link is a network company founded by Taiwan D-Link Group. It is committed to the research and development, production and marketing of local area networks, broadband networks, wireless networks, voice networks and related network equipment. Command injection vulnerabilities and multiple information disclosure vulnerabilities exist in multiple D-Link products. An attacker could use these vulnerabilities to gain access to potentially sensitive information and execute arbitrary commands in the context of an affected device

Trust: 1.89

sources: CNVD: CNVD-2013-02859 // CNVD: CNVD-2013-02860 // CNNVD: CNNVD-201304-110 // BID: 58938

IOT TAXONOMY

category:['IoT', 'Network device']sub_category: -

Trust: 1.2

sources: CNVD: CNVD-2013-02859 // CNVD: CNVD-2013-02860

AFFECTED PRODUCTS

vendor:d linkmodel:dir-600scope: - version: -

Trust: 1.2

vendor:d linkmodel:dir-300 revbscope: - version: -

Trust: 1.2

vendor:d linkmodel:dir-645scope: - version: -

Trust: 1.2

vendor:d linkmodel:dir-110scope: - version: -

Trust: 1.2

vendor:d linkmodel:dir-815scope: - version: -

Trust: 1.2

vendor:d linkmodel:dir-412scope: - version: -

Trust: 1.2

vendor:d linkmodel:dir-456scope: - version: -

Trust: 1.2

sources: CNVD: CNVD-2013-02859 // CNVD: CNVD-2013-02860

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2013-02859
value: HIGH

Trust: 0.6

CNVD: CNVD-2013-02860
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2013-02859
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

CNVD: CNVD-2013-02860
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2013-02859 // CNVD: CNVD-2013-02860

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201304-110

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 58938

PATCH

title:D-Link multiple product command injection vulnerability patchurl:https://www.cnvd.org.cn/patchinfo/show/33191

Trust: 0.6

title:D-Link patch for multiple product information disclosure vulnerabilitiesurl:https://www.cnvd.org.cn/patchinfo/show/33192

Trust: 0.6

sources: CNVD: CNVD-2013-02859 // CNVD: CNVD-2013-02860

EXTERNAL IDS

db:BIDid:58938

Trust: 2.1

db:EXPLOIT-DBid:24926

Trust: 1.2

db:CNVDid:CNVD-2013-02859

Trust: 0.6

db:CNVDid:CNVD-2013-02860

Trust: 0.6

db:CNNVDid:CNNVD-201304-110

Trust: 0.6

sources: CNVD: CNVD-2013-02859 // CNVD: CNVD-2013-02860 // BID: 58938 // CNNVD: CNNVD-201304-110

REFERENCES

url:http://www.exploit-db.com/exploits/24926/

Trust: 1.2

url:http://www.securityfocus.com/bid/58938

Trust: 0.6

url:http://www.dlink.com/

Trust: 0.3

sources: CNVD: CNVD-2013-02859 // CNVD: CNVD-2013-02860 // BID: 58938 // CNNVD: CNNVD-201304-110

CREDITS

m-1-k-3

Trust: 0.9

sources: BID: 58938 // CNNVD: CNNVD-201304-110

SOURCES

db:CNVDid:CNVD-2013-02859
db:CNVDid:CNVD-2013-02860
db:BIDid:58938
db:CNNVDid:CNNVD-201304-110

LAST UPDATE DATE

2022-05-17T01:51:12.684000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-02859date:2013-04-10T00:00:00
db:CNVDid:CNVD-2013-02860date:2013-04-10T00:00:00
db:BIDid:58938date:2013-04-11T05:28:00
db:CNNVDid:CNNVD-201304-110date:2013-04-12T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2013-02859date:2013-04-10T00:00:00
db:CNVDid:CNVD-2013-02860date:2013-04-10T00:00:00
db:BIDid:58938date:2013-04-05T00:00:00
db:CNNVDid:CNNVD-201304-110date:2013-04-12T00:00:00