ID

VAR-201801-1836


TITLE

D-Link DSL-6850U Router Remote Command Execution Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2018-00175

DESCRIPTION

D-LinkDSL-6850U is a wireless router product of D-Link. D-LinkDSL-6850U Router Remote Command Execution Vulnerability. Since the router has the remote web management service enabled by default, the service has the default credentials support:support and cannot be disabled. The attacker can log in to the router's web management interface through the default credentials, and then manually open the Wan port telnet service that is turned off by default. After logging in to the telnet service, you can use the && or || command sandbox escape to get full shell permissions.

Trust: 0.6

sources: CNVD: CNVD-2018-00175

IOT TAXONOMY

category:['IoT', 'Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-00175

AFFECTED PRODUCTS

vendor:d linkmodel:dsl-6850uscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2018-00175

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2018-00175
value: HIGH

Trust: 0.6

CNVD: CNVD-2018-00175
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2018-00175

PATCH

title:Patch for D-LinkDSL-6850U Router Remote Command Execution Vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/112429

Trust: 0.6

sources: CNVD: CNVD-2018-00175

EXTERNAL IDS

db:CNVDid:CNVD-2018-00175

Trust: 0.6

sources: CNVD: CNVD-2018-00175

REFERENCES

url:https://blogs.securiteam.com/index.php/archives/3588

Trust: 0.6

sources: CNVD: CNVD-2018-00175

SOURCES

db:CNVDid:CNVD-2018-00175

LAST UPDATE DATE

2022-05-04T10:04:28.420000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-00175date:2018-01-04T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-00175date:2018-01-04T00:00:00