D-Link DIR-600
cpe:2.3:o:dlink:dir-600_firmware:*:*:*:*:*:*:*, +2 more
- <= 2.14b01
This vulnerability is being actively exploited in the wild.
A command injection vulnerability has been identified in the web interface of several D-Link router models, specifically the DIR-600 rev B (firmware through 2.14b01) and DIR-300 rev B (firmware through 2.13). The issue arises in 'command.php', which fails to properly validate the 'cmd' POST parameter, allowing remote attackers to execute arbitrary commands without authentication. Exploitation of this vulnerability can be used to spawn a Telnet service on a specified port, providing persistent root access via an interactive shell.
Successful exploitation allows for unauthenticated OS command injection, with the potential to execute arbitrary commands as root. This vulnerability can also be exploited to start a Telnet service, providing an interactive shell with root privileges.
The vulnerability can be reproduced by sending a POST request to 'command.php' with an injected command in the 'cmd' parameter. The injection can be verified by checking the response for the command execution output. After successful exploitation, a Telnet service can be started on the router, which can be accessed to gain root shell access.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.