Showing 2 vulnerabilities on this page for dir-816_firmware

Signals CISA KEV Ransomware Nuclei
D-Link vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

D-Link dir-816_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

D-Link DIR-816 A2_v1.10CNB04.img is vulnerable to Command Injection via /goform/SystemCommand. After the user passes in the command parameter, it will be spliced into byte_4836B0 by snprintf, and finally doSystem(&byte_4836B0); will be executed, resulting in a command injection.

CWE-77CWE-78Aug 31, 2022
CVSS8.8v3.1EPSS8.45%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

D-Link dir-816_firmware Improper Neutralization of Special Elements used in a Command ('Command Injection')

An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 The HTTP request parameter is used in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user function. This can lead to command injection through shell metacharacters.

CWE-77Aug 24, 2021
CVSS9.8v3.1EPSS5.1%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX