Remote Code Execution Vulnerability in D-Link G416 Router
CVE-2023-50199
8.8HIGH
What is CVE-2023-50199?
The D-Link G416 router is vulnerable to remote code execution due to a lack of authentication on critical functions accessed via the HTTP service running on TCP port 80. Network-adjacent attackers can exploit this flaw to bypass authentication and execute malicious commands, compromising the security of the device and potentially gaining access to sensitive network information. Users are advised to review the vendor's security advisory for mitigation steps.
Affected Version(s)
G416 1.08b02
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published