A vulnerability classified as critical has been found in D-Link DAR-7000 up to 20240912. Affected is an unknown function of the file /view/DBManage/Backup_Server_commit.php. The manipulation of the argument host leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
History

Mon, 23 Sep 2024 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Dlink
Dlink dar-7000
Dlink dar-7000 Firmware
CPEs cpe:2.3:h:dlink:dar-7000:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dar-7000_firmware:*:*:*:*:*:*:*:*
Vendors & Products Dlink
Dlink dar-7000
Dlink dar-7000 Firmware

Fri, 20 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared D-link
D-link dar-7000
CPEs cpe:2.3:h:d-link:dar-7000:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link dar-7000
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 19 Sep 2024 21:15:00 +0000

Type Values Removed Values Added
Description A vulnerability classified as critical has been found in D-Link DAR-7000 up to 20240912. Affected is an unknown function of the file /view/DBManage/Backup_Server_commit.php. The manipulation of the argument host leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Title D-Link DAR-7000 Backup_Server_commit.php os command injection
Weaknesses CWE-78
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2024-09-19T21:00:10.914Z

Updated: 2024-09-20T14:40:00.225Z

Reserved: 2024-09-19T14:31:15.840Z

Link: CVE-2024-9004

cve-icon Vulnrichment

Updated: 2024-09-20T14:39:48.392Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-19T21:15:16.383

Modified: 2024-09-23T17:29:20.827

Link: CVE-2024-9004

cve-icon Redhat

No data.