Command Injection Vulnerability in D-Link DIR-2150 Router
CVE-2022-40720
8.8HIGH
Summary
The issue resides in the Dreambox plugin for the xupnpd service on D-Link DIR-2150 routers, which listens on TCP port 4044. Due to inadequate validation of user-supplied input, network-adjacent attackers can exploit this flaw to execute arbitrary commands on compromised routers. This vulnerability poses a significant risk as it does not require any form of authentication, enabling attackers to gain unauthorized control over the router, potentially leading to further network breaches or data loss.
Affected Version(s)
DIR-2150 4.0.1
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Anonymous