9
CVSSv2

CVE-2021-28144

Published: 11/03/2021 Updated: 28/06/2022
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

prog.cgi on D-Link DIR-3060 devices prior to 1.11b04 HF2 allows remote authenticated users to inject arbitrary commands in an admin or root context because SetVirtualServerSettings calls CheckArpTables, which calls popen unsafely.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dlink dir-3060 firmware

Exploits

D-Link DIR-3060 versions 111b04 and below suffer from an authenticated command injection vulnerability ...

Mailing Lists

IoT Inspector Research Lab Security Advisory IOT-20210311-0 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ title: Authenticated Command Injection in D-Link DIR-3060 Web Interface vendor/product: D-Link DIR-3060 (wwwdlinkcom/) vulnerable version: v111b04 & Bel ...