Multiple D-Link Products UPnP SOAP Interface Multiple Command Injection Vulnerabilities
BID:61005
Info
Multiple D-Link Products UPnP SOAP Interface Multiple Command Injection Vulnerabilities
| Bugtraq ID: | 61005 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 07 2013 12:00AM |
| Updated: | Jul 14 2014 12:08PM |
| Credit: | m-1-k-3 |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Multiple D-Link Products UPnP SOAP Interface Multiple Command Injection Vulnerabilities
Multiple D-Link products are prone to multiple command-injection vulnerabilities.
Exploiting these issues could allow an attacker to execute arbitrary commands in the context of the affected devices.
The following devices are vulnerable:
DIR-300 rev B running firmware 2.14b01
DIR-600 running firmware 2.16b01
DIR-645 running firmware 1.04b01
DIR-845 running firmware 1.01b02
DIR-865 running firmware 1.05b03
Multiple D-Link products are prone to multiple command-injection vulnerabilities.
Exploiting these issues could allow an attacker to execute arbitrary commands in the context of the affected devices.
The following devices are vulnerable:
DIR-300 rev B running firmware 2.14b01
DIR-600 running firmware 2.16b01
DIR-645 running firmware 1.04b01
DIR-845 running firmware 1.01b02
DIR-865 running firmware 1.05b03
Exploit / POC
Multiple D-Link Products UPnP SOAP Interface Multiple Command Injection Vulnerabilities
An attacker can exploit these issues through a browser.
The following example data and exploit codes are available:
An attacker can exploit these issues through a browser.
The following example data and exploit codes are available:
Solution / Fix
Multiple D-Link Products UPnP SOAP Interface Multiple Command Injection Vulnerabilities
Solution:
Reportedly these issues are fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly these issues are fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
Multiple D-Link Products UPnP SOAP Interface Multiple Command Injection Vulnerabilities
References:
References:
- D-Link Homepage (D-Link)