On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can forge an HTTP request to inject operating system commands that can be executed on the device with higher privileges, aka remote code execution.
2018-05-18T14:29:00.217
2024-11-21T03:42:24.650
Modified
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | d-link | dir-550a_firmware | ≤ 2.10kr | Yes |
Hardware | dlink | dir-550a | - | No |
Operating System | d-link | dir-604m_firmware | ≤ 2.10kr | Yes |
Hardware | dlink | dir-604m | - | No |