D-Link DIR-X3260 SetSysEmailSettings SMTPServerAddress Command Injection Remote Code Execution Vulnerability
CVE-2023-44427

8HIGH

Key Information:

Vendor
D-link
Status
Vendor
CVE Published:
3 May 2024

Summary

The identified vulnerability in the D-Link DIR-X3260 router arises from a flaw in the handling of HNAP requests by the prog.cgi component. This vulnerability allows network-adjacent attackers to exploit improper validation processes to inject commands and execute arbitrary code. Although authentication is typically required, attackers can bypass existing mechanisms, paving the way for potential exploitation. The vulnerability particularly affects the lighttpd web server listening on TCP ports 80 and 443, enabling heightened risks for unprotected networks, especially if the router is configured to an insecure state.

Affected Version(s)

DIR-X3260 1.02B02

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.