CVE-2013-5945
Summary
| CVE | CVE-2013-5945 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-11 12:15:00 UTC |
| Updated | 2021-04-23 18:13:00 UTC |
| Description | Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 allow remote attackers to execute arbitrary SQL commands via the password to (1) the login.authenticate function in share/lua/5.1/teamf1lualib/login.lua or (2) captivePortal.lua. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Dlink | Dsr-1000 | - | All | All | All |
| Hardware | Dlink | Dsr-1000 | - | All | All | All |
| Hardware | Dlink | Dsr-1000n | - | All | All | All |
| Hardware | Dlink | Dsr-1000n | - | All | All | All |
| Operating System | Dlink | Dsr-1000n Firmware | All | All | All | All |
| Operating System | Dlink | Dsr-1000n Firmware | All | All | All | All |
| Operating System | Dlink | Dsr-1000 Firmware | All | All | All | All |
| Operating System | Dlink | Dsr-1000 Firmware | All | All | All | All |
| Hardware | Dlink | Dsr-150 | - | All | All | All |
| Hardware | Dlink | Dsr-150 | - | All | All | All |
| Hardware | Dlink | Dsr-150n | - | All | All | All |
| Hardware | Dlink | Dsr-150n | - | All | All | All |
| Operating System | Dlink | Dsr-150n Firmware | All | All | All | All |
| Operating System | Dlink | Dsr-150n Firmware | All | All | All | All |
| Operating System | Dlink | Dsr-150 Firmware | All | All | All | All |
| Operating System | Dlink | Dsr-150 Firmware | All | All | All | All |
| Hardware | Dlink | Dsr-250 | - | All | All | All |
| Hardware | Dlink | Dsr-250 | - | All | All | All |
| Hardware | Dlink | Dsr-250n | - | All | All | All |
| Hardware | Dlink | Dsr-250n | - | All | All | All |
| Operating System | Dlink | Dsr-250n Firmware | All | All | All | All |
| Operating System | Dlink | Dsr-250n Firmware | All | All | All | All |
| Operating System | Dlink | Dsr-250 Firmware | All | All | All | All |
| Operating System | Dlink | Dsr-250 Firmware | All | All | All | All |
| Hardware | Dlink | Dsr-500 | - | All | All | All |
| Hardware | Dlink | Dsr-500 | - | All | All | All |
| Hardware | Dlink | Dsr-500n | - | All | All | All |
| Hardware | Dlink | Dsr-500n | - | All | All | All |
| Operating System | Dlink | Dsr-500n Firmware | All | All | All | All |
| Operating System | Dlink | Dsr-500n Firmware | All | All | All | All |
| Operating System | Dlink | Dsr-500 Firmware | All | All | All | All |
| Operating System | Dlink | Dsr-500 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| tsd.dlink.com.tw/temp/PMD/12966/DSR-150_A1_A2_Release_Notes_FW_v1.08B44_WW.pdf | MISC | tsd.dlink.com.tw | Broken Link |
| tsd.dlink.com.tw/temp/PMD/13039/DSR-250_250N_A1_A2_Release_Notes_FW_v1.08B44_W... | MISC | tsd.dlink.com.tw | Broken Link |
| Zine: D-Link DSR Router Series - Remote Command Execution - Multiple papers Exploit | MISC | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| tsd.dlink.com.tw/temp/PMD/12879/DSR-500_500N_1000_1000N_A1_Release_Notes_FW_v1... | MISC | tsd.dlink.com.tw | Broken Link |
| tsd.dlink.com.tw/temp/PMD/12960/DSR-150N_A2_Release_Notes_FW_v1.05B64_WW.pdf | MISC | tsd.dlink.com.tw | Broken Link |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.