D-Link DIR-868L
cpe:2.3:h:d-link:dir-868l:*:*:*:*:*:*:*, +5 more
- 110b03
A critical OS command injection vulnerability has been identified in the D-Link DIR-868L router, specifically in the SSDP service function 'sub_1BF84'. This vulnerability arises from improper handling of the 'ST' argument, allowing remote, unauthenticated attackers to execute arbitrary OS commands. The issue affects version 110b03 of the DIR-868L model, which is no longer supported by the manufacturer.
Exploitation of this vulnerability allows for pre-authentication OS command injection, with the potential for full system compromise.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.