CVE-2023-44959

HIGH

D-Link DSL-3782 Firmware < 1.03 - Authenticated Remote Code Execution via Router IP Address Field

Title source: llm
STIX 2.1

Description

An issue found in D-Link DSL-3782 v.1.03 and before allows remote authenticated users to execute arbitrary code as root via the Router IP Address fields of the network settings page.

Scores

CVSS v3 8.8
EPSS 0.4706
EPSS Percentile 97.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Products (1)
dlink/dsl-3782_firmware < 1.03
Published Oct 10, 2023
Tracked Since Feb 18, 2026