An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the date parameter in a system_time.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affected.
2020-03-07T01:15:15.377
2024-11-21T04:54:59.147
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | dlink | dir-825_firmware | 2.10 | Yes |
Hardware | dlink | dir-825 | - | No |
Operating System | trendnet | tew-632brp_firmware | 1.010b32 | Yes |
Hardware | trendnet | tew-632brp | - | No |