D-Link DIR-816
cpe:2.3:h:d-link:dir-816:*:*:*:*:*:*:*, +8 more
- A2V1.1.0B05
A command injection vulnerability has been identified in the D-Link DIR-816 A2V1.1.0B05 model. The issue resides in the web interface component, specifically within the 'iptablesWebsFilterRun' function. This vulnerability allows remote attackers to execute arbitrary commands by injecting malicious payloads through the 'websURLFilters' parameter. The injected commands are then executed via the system function, without any proper validation or sanitization.
Exploitation of this vulnerability allows for arbitrary command execution on the affected device.
To reproduce this vulnerability, first obtain the token ID by sending a request to the login page and extracting the token from the response. Then, send a POST request to '/goform/websHostFilterDelete' with the injected command, such as 'reboot', included in the 'websURLFilters' parameter, along with the token ID.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.