vendor:
DIR-601
by:
Samuel Huntley
N/A
CVSS
N/A
Command Injection
Unknown
CWE
Product Name: DIR-601
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE:
CPE: cpe:2.3:h:d-link:dir-601:*:*:*:*:*:*:*:*
Platforms Tested:
Unknown
DIR-601 Command injection in ping functionality
The DIR-601 firmware has a security issue that allows an attacker to exploit command injection in the ping functionality. The attacker needs to be logged in, and can execute the attack either from the wireless LAN or if the management interface is exposed on the Internet. XSRF can also be used to trick the administrator into exploiting the vulnerability.
Mitigation:
The vendor has fixed the issues and released firmware updates. Users of the affected devices should update their router firmware to mitigate the vulnerability.