D-Link DIR-832X Command Injection Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A command injection vulnerability has been identified in the D-Link DIR-832X router, specifically in the 240802 firmware version. This vulnerability allows remote, unauthenticated attackers to execute arbitrary commands with root privileges. The issue arises in the 'diag_traceroute' function, where the 'target_addr' parameter can be manipulated to inject commands.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the device, with root privileges.

Reproduction

To reproduce this vulnerability, log into the router's web interface and navigate to the 'diag_traceroute' function. Inject a command through the 'target_addr' parameter, ensuring that the input bypasses validation checks. Once the command is executed, a file named 'hack_diag_traceroute.txt' will be created, indicating successful exploitation.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.2
impact
7.5
exploitability
7.5
remediation
0.0
relevance
0.0
threat
6.5
urgency
2.9
incentive
9.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.