Record summary

CVE-2021-3708 has a selected CVSS score of 7.8 (high); EIP currently links 1 repository PoC.

Description

D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to OS command injection. An unauthenticated attacker on the local network may exploit this, with CVE-2021-3707, to execute any OS commands on the vulnerable device.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 19, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE Listfirmware vME1.16 or prior versionsaffected
VulnCheckVersion data not supplied

Proofs of concept

1

Repository PoCs

GitHubHadiMed/DSL-2750U-Full-chainRepository PoCby HadiMedStars: 21Not analyzed9 files

163.2 KiB · linked to 2 vulnerabilities

GitHub

PoC details

References

5