D-Link DIR-823x
cpe:2.3:h:d-link:dir-823:*:*:*:*:*:*:*, +6 more
- 240802
A command injection vulnerability has been identified in the D-Link DIR-823X router, specifically in the 240802 firmware version. This vulnerability allows remote, unauthenticated attackers to execute arbitrary commands with root privileges. The issue arises in the 'diag_ping' function, where the 'target_addr' parameter can be manipulated to inject malicious commands.
Exploitation of this vulnerability allows for arbitrary command execution on the device with root privileges.
The vulnerability can be reproduced by sending a POST request to the '/goform/diag_ping' endpoint. The 'target_addr' parameter must be crafted to include the desired command injection payload. After the request is processed, the injected command will be executed on the router's operating system.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.