ID

VAR-201407-0749


TITLE

Multiple D-Link Products 'soap.cgi' Remote Command Injection Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2014-04505

DESCRIPTION

The D-Link DIR series is a router device developed by D-LINK. Multiple D-Link DIR series products soap.cgi failed to properly filter the \"NewInternalClient\", \"NewExternalPort\" and \"NewInternalPort\" XML parameter data, allowing remote attackers to exploit the vulnerability to inject and execute arbitrary shell commands.

Trust: 0.6

sources: CNVD: CNVD-2014-04505

IOT TAXONOMY

category:['IoT', 'Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-04505

AFFECTED PRODUCTS

vendor:d linkmodel:dir-300scope: - version: -

Trust: 0.6

vendor:d linkmodel:dir-600scope: - version: -

Trust: 0.6

vendor:d linkmodel:dir-645scope:eqversion:1.x

Trust: 0.6

vendor:d linkmodel:dir-865lscope: - version: -

Trust: 0.6

vendor:d linkmodel:dir-845lscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2014-04505

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2014-04505
value: HIGH

Trust: 0.6

CNVD: CNVD-2014-04505
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2014-04505

PATCH

title:Patch for multiple D-Link products 'soap.cgi' remote command injection vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/47624

Trust: 0.6

sources: CNVD: CNVD-2014-04505

EXTERNAL IDS

db:SECUNIAid:59274

Trust: 0.6

db:CNVDid:CNVD-2014-04505

Trust: 0.6

sources: CNVD: CNVD-2014-04505

REFERENCES

url:http://www.s3cur1ty.de/m1adv2013-020

Trust: 0.6

url:http://secunia.com/advisories/59274/

Trust: 0.6

sources: CNVD: CNVD-2014-04505

SOURCES

db:CNVDid:CNVD-2014-04505

LAST UPDATE DATE

2022-05-17T01:43:22.395000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-04505date:2014-07-29T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2014-04505date:2014-07-23T00:00:00