The DHCP client on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices allows unauthenticated remote code execution as root because /etc/services/INET/inet_ipv4.php mishandles shell metacharacters, affecting generated files such as WAN-1-udhcpc.sh.
2017-09-13T17:29:00.870
2025-05-06T15:15:50.277
Deferred
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | dlink | dir-850l_firmware | < fw114wwb07_h2ab | Yes |
Operating System | dlink | dir-850l_firmware | fw114wwb07_h2ab | Yes |
Hardware | dlink | dir-850l | - | No |
Operating System | dlink | dir-850l_firmware | ≤ fw208wwb02 | Yes |
Hardware | dlink | dir-850l | - | No |