github.com
https://github.com/HadiMed/firmware-analysis/blob/main/DSL-2750U%20%28firmware%20version%201.6%29/README.md CVE-2021-3708
HIGH
D-Link dsl-2750u_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2021-3708 has a selected CVSS score of 7.8 (high); EIP currently links 1 repository PoC.
Description
D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to OS command injection. An unauthenticated attacker on the local network may exploit this, with CVE-2021-3707, to execute any OS commands on the vulnerable device.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 19, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Repository PoCs
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
DSL-2750UBrowse D-Link / DSL-2750U | CVE List | firmware vME1.16 or prior versions | affected |
dsl-2750u_firmwareBrowse D-Link / dsl-2750u_firmware | VulnCheck | Version data not supplied | |
Proofs of concept
1Repository PoCs
GitHubHadiMed/DSL-2750U-Full-chainRepository PoCby HadiMedStars: 21Not analyzed9 files
References
5github.com
https://github.com/HadiMed/firmware-analysis/blob/main/DSL-2750U%20(firmware%20version%201.6)/README.md JVNVU#92088210: Multiple vulnerabilities in D-Link router DSL-2750UThird-party advisory
https://jvn.jp/en/vu/JVNVU92088210 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-3708 supportannouncement.us.dlink.comConfirmation
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10230