Command Injection Vulnerability in D-Link DIR-815 Router Firmware
CVE-2024-22651
9.8CRITICAL
Summary
A command injection vulnerability exists in the ssdpcgi_main function of the CGI binary in the firmware of D-Link DIR-815 routers, specifically in version 1.04. This loophole allows an attacker with network access to execute arbitrary commands on the affected system, potentially compromising the router's functionality and network security. It is crucial for users to update their firmware to mitigate this risk and improve overall security.
References
EPSS Score
22% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved