Command Injection Vulnerability in D-Link DI-8100
CVE-2024-7436

8.8HIGH

Key Information:

Vendor
D-Link
Vendor
CVE Published:
3 August 2024

Summary

A critical command injection vulnerability has been identified in the D-Link DI-8100 device, specifically within the msp_info.htm functionality. This issue arises due to improper validation of the 'cmd' parameter, leading to potential manipulation by attackers. As a result, remote exploitation of this vulnerability can allow malicious actors to execute arbitrary commands on the affected system. The severity of this vulnerability necessitates immediate attention from users to mitigate the risk of unauthorized access or control over affected devices. Refer to VDB-273521 for more details and updates on this serious security concern.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.