Command Injection Vulnerability in D-Link DAP-X1860 Repeater
CVE-2023-45208
8.8HIGH
What is CVE-2023-45208?
The D-Link DAP-X1860 repeater is vulnerable to a command injection issue in the parsing_xml_stasurvey function within libcgifunc.so. Attackers within proximity can exploit this vulnerability by providing a specially crafted SSID during the setup phase. This may allow them to execute arbitrary shell commands with root privileges. Moreover, using network names that include single quotes can lead to a denial of service, compromising the device's availability.