CVE-2023-25280
D-Link DIR-820 Router OS Command Injection Vulnerability
Record summary
CVE-2023-25280 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template. CISA lists CVE-2023-25280 in KEV.
Description
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.
Exploitation context
Known exploitation
- CISA KEV
- Listed · Sep 30, 2024 · CISA
- VulnCheck KEV
- Listed · Jun 22, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 4, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
DIR-820 RouterBrowse D-Link / DIR-820 Router | CISA | Version data not supplied | |
dir820la1_firmwareBrowse dlink / dir820la1_firmwareDefault status: unknown | CVE List | 105b03 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALD-Link DIR820LA1_FW105B03 'ping_addr' - OS Command InjectionCVSS 9.8
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.
Impact
Unauthenticated attackers can execute arbitrary OS commands with root privileges on the D-Link DIR820LA1 router, leading to complete device compromise and network takeover.
Remediation
Upgrade to the latest firmware version from D-Link or replace the affected device with a patched model.
Source: ProjectDiscovery