Command Injection Vulnerability in D-Link DIR-2150 Router
CVE-2022-40720

8.8HIGH

Key Information:

Vendor
D-link
Status
Vendor
CVE Published:
26 January 2023

Summary

The issue resides in the Dreambox plugin for the xupnpd service on D-Link DIR-2150 routers, which listens on TCP port 4044. Due to inadequate validation of user-supplied input, network-adjacent attackers can exploit this flaw to execute arbitrary commands on compromised routers. This vulnerability poses a significant risk as it does not require any form of authentication, enabling attackers to gain unauthorized control over the router, potentially leading to further network breaches or data loss.

Affected Version(s)

DIR-2150 4.0.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

CVSS V3.0

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Anonymous
.