D-Link D-View Command Injection Remote Code Execution Vulnerability
CVE-2024-5297
8.8HIGH
What is CVE-2024-5297?
A significant command injection vulnerability exists in D-Link D-View, allowing remote attackers to execute arbitrary code on the affected systems. This issue arises from improper validation of user-supplied strings in the executeWmicCmd method, which is utilized to execute system calls. While successful exploitation of this weakness requires authentication, the authentication mechanism can be bypassed, enabling unauthorized access to execute commands with root privileges.
Affected Version(s)
D-View 2.0.1.28