D-Link DIR-X3260 SetSysEmailSettings SMTPServerAddress Command Injection Remote Code Execution Vulnerability
CVE-2023-44427
What is CVE-2023-44427?
The identified vulnerability in the D-Link DIR-X3260 router arises from a flaw in the handling of HNAP requests by the prog.cgi component. This vulnerability allows network-adjacent attackers to exploit improper validation processes to inject commands and execute arbitrary code. Although authentication is typically required, attackers can bypass existing mechanisms, paving the way for potential exploitation. The vulnerability particularly affects the lighttpd web server listening on TCP ports 80 and 443, enabling heightened risks for unprotected networks, especially if the router is configured to an insecure state.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DIR-X3260 1.02B02
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved