sek1th

4 exploits Active since Sep 2020
CVE-2020-25366 WRITEUP CRITICAL WRITEUP
Dlink Dir-823g Firmware - Missing Authorization
An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a denial of service (DoS) via unspecified vectors.
CVSS 9.1
CVE-2020-25367 WRITEUP CRITICAL WRITEUP
Dlink Dir-823g Firmware - OS Command Injection
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha field to Login.
CVSS 9.8
CVE-2020-25368 WRITEUP CRITICAL WRITEUP
Dlink Dir-823g Firmware - OS Command Injection
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the PrivateLogin field to Login.
CVSS 9.8
CVE-2020-25786 WRITEUP MEDIUM WRITEUP
Dlink Dir-803 Firmware - XSS
webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: this is typically not exploitable because of URL encoding (except in Internet Explorer) and because a web page cannot specify that a client should make an additional HTTP request with an arbitrary Referer header
CVSS 6.1