Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 allow remote attackers to execute arbitrary SQL commands via the password to (1) the login.authenticate function in share/lua/5.1/teamf1lualib/login.lua or (2) captivePortal.lua.
2020-02-11T12:15:11.757
2024-11-21T01:58:28.210
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | dlink | dsr-150_firmware | < 1.08b44 | Yes |
Hardware | dlink | dsr-150 | - | No |
Operating System | dlink | dsr-150n_firmware | < 1.05b64 | Yes |
Hardware | dlink | dsr-150n | - | No |
Operating System | dlink | dsr-250_firmware | < 1.08b44 | Yes |
Hardware | dlink | dsr-250 | - | No |
Operating System | dlink | dsr-250n_firmware | < 1.08b44 | Yes |
Hardware | dlink | dsr-250n | - | No |
Operating System | dlink | dsr-500_firmware | < 1.08b77 | Yes |
Hardware | dlink | dsr-500 | - | No |
Operating System | dlink | dsr-500n_firmware | < 1.08b77 | Yes |
Hardware | dlink | dsr-500n | - | No |
Operating System | dlink | dsr-1000_firmware | < 1.08b77 | Yes |
Hardware | dlink | dsr-1000 | - | No |
Operating System | dlink | dsr-1000n_firmware | < 1.08b77 | Yes |
Hardware | dlink | dsr-1000n | - | No |