D-Link Routers tools_vct.htm OS Command Injection
Vulnerability Description
An authenticated OS command injection vulnerability exists in various D-Link routers (tested on DIR-615H1 running firmware version 8.04) via the tools_vct.htm endpoint. The web interface fails to sanitize input passed from the ping_ipaddr parameter to the tools_vct.htm diagnostic interface, allowing attackers to inject arbitrary shell commands using backtick encapsulation. With default credentials, an attacker can exploit this blind injection vector to execute arbitrary commands.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-10059
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Michael Messner
References
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/http/dlink_dir615_up_exec.rb
- https://www.exploit-db.com/exploits/24477
- https://www.exploit-db.com/exploits/25609
- https://web.archive.org/web/20150921102603/http://www.s3cur1ty.de/m1adv2013-008
- https://www.vulncheck.com/advisories/d-link-legacy-os-command-injection
More from D-Link
View All →Affected Vendor
D-Link
View all reports →