D-Link DIR-X3260 SetSysEmailSettings SMTPServerAddress Command Injection Remote Code Execution Vulnerability
CVE-2023-44427
8HIGH
Summary
The identified vulnerability in the D-Link DIR-X3260 router arises from a flaw in the handling of HNAP requests by the prog.cgi component. This vulnerability allows network-adjacent attackers to exploit improper validation processes to inject commands and execute arbitrary code. Although authentication is typically required, attackers can bypass existing mechanisms, paving the way for potential exploitation. The vulnerability particularly affects the lighttpd web server listening on TCP ports 80 and 443, enabling heightened risks for unprotected networks, especially if the router is configured to an insecure state.
Affected Version(s)
DIR-X3260 1.02B02
References
CVSS V3.1
Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved