Command Injection Vulnerability in D-Link DI-8100
CVE-2024-7436
8.8HIGH
Summary
A critical command injection vulnerability has been identified in the D-Link DI-8100 device, specifically within the msp_info.htm functionality. This issue arises due to improper validation of the 'cmd' parameter, leading to potential manipulation by attackers. As a result, remote exploitation of this vulnerability can allow malicious actors to execute arbitrary commands on the affected system. The severity of this vulnerability necessitates immediate attention from users to mitigate the risk of unauthorized access or control over affected devices. Refer to VDB-273521 for more details and updates on this serious security concern.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published