Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-5945


Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 allow remote attackers to execute arbitrary SQL commands via the password to (1) the login.authenticate function in share/lua/5.1/teamf1lualib/login.lua or (2) captivePortal.lua.


Published

2020-02-11T12:15:11.757

Last Modified

2024-11-21T01:58:28.210

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System dlink dsr-150_firmware < 1.08b44 Yes
Hardware dlink dsr-150 - No
Operating System dlink dsr-150n_firmware < 1.05b64 Yes
Hardware dlink dsr-150n - No
Operating System dlink dsr-250_firmware < 1.08b44 Yes
Hardware dlink dsr-250 - No
Operating System dlink dsr-250n_firmware < 1.08b44 Yes
Hardware dlink dsr-250n - No
Operating System dlink dsr-500_firmware < 1.08b77 Yes
Hardware dlink dsr-500 - No
Operating System dlink dsr-500n_firmware < 1.08b77 Yes
Hardware dlink dsr-500n - No
Operating System dlink dsr-1000_firmware < 1.08b77 Yes
Hardware dlink dsr-1000 - No
Operating System dlink dsr-1000n_firmware < 1.08b77 Yes
Hardware dlink dsr-1000n - No

References