diag_ping.cmd on D-Link DSL-2640U devices with firmware IM_1.00 and ME_1.00, and DSL-2540U devices with firmware ME_1.00, allows authenticated remote attackers to execute arbitrary OS commands via shell metacharacters in the ipaddr field of an HTTP GET request.
2018-01-12T09:29:01.853
2024-11-21T04:08:40.747
Modified
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | d-link | dsl-2540u_firmware | me_1.00 | Yes |
Hardware | dlink | dsl-2540u | - | No |
Operating System | d-link | dsl-2640u_firmware | im_1.00 | Yes |
Operating System | d-link | dsl-2640u_firmware | me_1.00 | Yes |
Hardware | dlink | dsl-2640u | - | No |