Record summary

CVE-2023-25280 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template. CISA lists CVE-2023-25280 in KEV.

Description

OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Sep 30, 2024 · CISA
VulnCheck KEV
Listed · Jun 22, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationActive
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 4, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CISAVersion data not supplied

Default status: unknown

CVE List105b03affected

Nuclei templates

1
ProjectDiscoveryCRITICALD-Link DIR820LA1_FW105B03 'ping_addr' - OS Command InjectionCVSS 9.8

OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.

Impact

Unauthenticated attackers can execute arbitrary OS commands with root privileges on the D-Link DIR820LA1 router, leading to complete device compromise and network takeover.

Remediation

Upgrade to the latest firmware version from D-Link or replace the affected device with a patched model.

WeaknessesCWE-78
Authorspussycat0x
Template tagscvecve2023rceunauthkevdlinkvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:dlink:dir820la1_firmware:105b03:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

4