vendor:
Various D-Link Routers
by:
Michael Messner, juan vazquez
7.5
CVSS
HIGH
OS command injection
78
CWE
Product Name: Various D-Link Routers
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Unix
2013
D-Link Devices UPnP SOAP Telnetd Command Execution
Various D-Link Routers are vulnerable to OS command injection in the UPnP SOAP interface. This module has been tested successfully on DIR-300, DIR-600, DIR-645, DIR-845 and DIR-865. According to the vulnerability discoverer, more D-Link devices may be affected.
Mitigation:
Apply the latest firmware update provided by D-Link.