8.8
CVSSv3

CVE-2021-28144

Published: 11/03/2021 Updated: 23/04/2021
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

prog.cgi on D-Link DIR-3060 devices prior to 1.11b04 HF2 allows remote authenticated users to inject arbitrary commands in an admin or root context because SetVirtualServerSettings calls CheckArpTables, which calls popen unsafely.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dlink dir-3060_firmware

Exploits

D-Link DIR-3060 versions 111b04 and below suffer from an authenticated command injection vulnerability ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> [CVE-2021-28144] Authenticated Command Injection in D-Link DIR-3060 Web Interface <!--X-Subject-Header-End--> <!--X-He ...