D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the ExternalPort, InternalPort, ProtocolNumber, and LocalIPAddress parameters in the SetVirtualServerSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
History

Thu, 17 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Dlink
Dlink dir-878 Firmware
Dlink dir-882 Firmware
Weaknesses CWE-78
CPEs cpe:2.3:o:dlink:dir-878_firmware:1.30b08:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-882_firmware:1.30b06:*:*:*:*:*:*:*
Vendors & Products Dlink
Dlink dir-878 Firmware
Dlink dir-882 Firmware
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Oct 2024 17:30:00 +0000

Type Values Removed Values Added
Description D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the ExternalPort, InternalPort, ProtocolNumber, and LocalIPAddress parameters in the SetVirtualServerSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-10-17T00:00:00

Updated: 2024-10-17T19:04:11.450Z

Reserved: 2024-10-08T00:00:00

Link: CVE-2024-48633

cve-icon Vulnrichment

Updated: 2024-10-17T19:02:58.375Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-17T18:15:08.447

Modified: 2024-10-18T12:52:33.507

Link: CVE-2024-48633

cve-icon Redhat

No data.