Record summary

CVE-2023-4542 has a selected CVSS score of 6.3 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

A vulnerability was found in D-Link DAR-8000-10 up to 20230809. It has been classified as critical. This affects an unknown part of the file /app/sys1.php. The manipulation of the argument cmd with the input id leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-238047. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 18, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List20230809affected
VulnCheckVersion data not supplied

Proofs of concept

1

Repository PoCs

GitHubPumpkinBridge/CVE-2023-4542Repository PoCby PumpkinBridgeStars: 2Not analyzed2 files

2.5 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALD-Link DAR-8000-10 - Command InjectionCVSS 9.8

D-Link DAR-8000-10 version has an operating system command injection vulnerability. The vulnerability originates from the parameter id of the file /app/sys1.php which can lead to operating system command injection.

Impact

Unauthenticated attackers can execute arbitrary operating system commands through the id parameter in /app/sys1.php, potentially gaining full control of the D-Link DAR-8000-10 router and intercepting all network traffic.

Remediation

Update D-Link DAR-8000-10 firmware to a patched version that properly sanitizes the id parameter in sys1.php and prevents operating system command injection.

WeaknessesCWE-78
Authorspussycat0x
Template tagscvecve2023dlinkvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:dlink:dar-8000-10_firmware:*:*:*:*:*:*:*:*
FOFA: body="DAR-8000-10" && title="D-Link"
FOFA: body="dar-8000-10" && title="d-link"

Source: ProjectDiscovery

References

4