D-Link DSL-7740C
cpe:2.3:h:d-link:dsl-7740c:*:*:*:*:*:*:*, +1 more
- DSL7740C.V6.TR069.20211230
A command injection vulnerability has been identified in the D-Link DSL-7740C router, specifically in the firmware version DSL7740C.V6.TR069.20211230. The vulnerability arises in the backup function when accessed via SSH or Telnet, allowing remote execution of arbitrary commands with elevated privileges.
Exploitation of this vulnerability could lead to complete compromise of the device, allowing attackers to execute arbitrary commands with administrative rights. This could disrupt service, alter device configurations, manipulate traffic, and potentially breach the network perimeter to access sensitive areas of the network.
The vulnerability can be reproduced by sending a specially crafted payload through the backup function via SSH or Telnet. After logging in with administrative credentials, navigate to the '21. Configuration' menu and select '03 Backup.' During a ping test, enter a payload that includes a command, such as one that uses 'wget' to download a file to the device.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.