Code Execution Vulnerability in D-Link DIR-1935 Routers
CVE-2022-43623
6.8MEDIUM
Summary
A critical vulnerability in D-Link DIR-1935 routers enables network-adjacent attackers to execute arbitrary code on affected installations. Through manipulation of the SetWebFilterSetting requests in the web management portal, attackers can bypass existing authentication and exploit the flaw in handling user-supplied strings when parsing the WebFilterURLs element. This allows execution of system calls in the context of root, potentially compromising the integrity and confidentiality of the device.
Affected Version(s)
DIR-1935 1.03
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Anonymous