D-Link DIR-615
cpe:2.3:h:d-link:dir-615:*:*:*:*:*:*:*, +3 more
- 4.10
A command injection vulnerability has been identified in the D-Link DIR-615 router, specifically in version 4.10. This issue arises within the 'Advanced Firewall' settings, in the DMZ Host feature, where the 'dmz_ipaddr' parameter can be manipulated to inject operating system commands. The vulnerability can be exploited remotely by authenticated users with administrative access, allowing injected commands to be executed with root privileges.
Exploitation of this vulnerability allows for arbitrary operating system command execution with root privileges on the affected device.
To reproduce this vulnerability, an authenticated user with administrative rights must access the router's web interface and navigate to the 'Advanced Firewall' settings. Once there, the DMZ Host feature can be enabled. The user must then inject shell metacharacters into the 'dmz_ipaddr' parameter, which will be saved to the device's NVRAM. When the changes are applied, the injected commands will be executed by the system with root privileges.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.