D-Link DIR-2150 SetNTPServerSettings Command Injection Remote Code Execution Vulnerability
CVE-2023-34275
What is CVE-2023-34275?
The vulnerability present in D-Link DIR-2150 routers permits network-adjacent attackers to execute arbitrary code through a command injection flaw in the SOAP API interface. This critical issue arises from insufficient validation of user-supplied strings prior to executing system calls. While the vulnerability requires authentication for exploitation, an attacker can bypass the existing authentication mechanisms. By leveraging this vulnerability, an attacker can gain root-level access to the affected system, undermining the security integrity of the device and potentially leading to further exploitation within the network.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DIR-2150 1.05B01
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved