ID

VAR-201708-1646


TITLE

D-Link DIR Series Router Remote Command Execution Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2017-20001

DESCRIPTION

The DIR series is a series of cloud router products from D-Link. A remote command execution vulnerability exists in the D-LinkDIR series router. The attacker can obtain the router background login credentials and execute arbitrary code through the router public network portal.

Trust: 0.6

sources: CNVD: CNVD-2017-20001

IOT TAXONOMY

category:['IoT', 'Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-20001

AFFECTED PRODUCTS

vendor:d linkmodel:dir-815scope: - version: -

Trust: 0.6

vendor:d linkmodel:dir-868lscope: - version: -

Trust: 0.6

vendor:d linkmodel:dir-860lscope: - version: -

Trust: 0.6

vendor:d linkmodel:dir-890lscope: - version: -

Trust: 0.6

vendor:d linkmodel:dir-610lscope: - version: -

Trust: 0.6

vendor:d linkmodel:dir-822scope: - version: -

Trust: 0.6

vendor:d linkmodel:dir-600scope: - version: -

Trust: 0.6

vendor:d linkmodel:dir-850lscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2017-20001

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2017-20001
value: HIGH

Trust: 0.6

CNVD: CNVD-2017-20001
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2017-20001

PATCH

title:Patch for D-LinkDIR Series Router Remote Command Execution Vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/99780

Trust: 0.6

sources: CNVD: CNVD-2017-20001

EXTERNAL IDS

db:CNVDid:CNVD-2017-20001

Trust: 0.6

sources: CNVD: CNVD-2017-20001

REFERENCES

url:https://blogs.securiteam.com/index.php/archives/3364

Trust: 0.6

sources: CNVD: CNVD-2017-20001

SOURCES

db:CNVDid:CNVD-2017-20001

LAST UPDATE DATE

2022-05-04T08:39:29.740000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-20001date:2017-08-10T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-20001date:2017-08-10T00:00:00