An OS command injection vulnerability exists in various legacy D-Link routers—including DIR-300 rev B and DIR-600 (firmware ≤ 2.13 and ≤ 2.14b01, respectively)—due to improper input handling in the unauthenticated command.php endpoint. By sending specially crafted POST requests, a remote attacker can execute arbitrary shell commands with root privileges, allowing full takeover of the device. This includes launching services such as Telnet, exfiltrating credentials, modifying system configuration, and disrupting availability. The flaw stems from the lack of authentication and inadequate sanitation of the cmd parameter.
The command.php endpoint accepts HTTP POST requests without any authentication mechanism. The cmd parameter passed in the request body is not properly sanitized, which allows an attacker to inject arbitrary system commands. These commands are executed directly by the device's operating system with root privileges. It is sufficient to send a crafted POST request over the network, without the need to possess any login credentials.
The attacker gains full control of the device with root privileges, which enables launching services such as Telnet, stealing authentication credentials, modifying system configuration, and disrupting device availability.
Apply patches available from the manufacturer according to the references. Due to the legacy status of the devices, it is recommended to verify firmware update availability from the manufacturer, and in case of unavailability — isolate the devices from the public Internet and restrict access to the management interface exclusively to trusted hosts on the local network. Consider replacing the devices with current models supported by the manufacturer.
D-Link DIR-300 rev B and D-Link DIR-600 with firmware version ≤ 2.13 (DIR-300) and ≤ 2.14b01 (DIR-600)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XDlink Dir 300
HWDlinkall versionsDlink Dir 300 Firmware
OSDlink≤ 2.13Dlink Dir 600
HWDlinkall versionsDlink Dir 600 Firmware
OSDlink≤ 2.14b01
Related vulnerabilities
D-Link DIR-series — nieuwierzytelniony command injection w service.cgi (root RCE)
D-Link DIR-300/DIR-600 — nieuwierzytelniony OS command injection w command.php
D-Link DIR-300: zakodowane na stałe dane uwierzytelniające w usłudze Telnet
Command injection w routerze D-Link DIR-600 via parametr ST
Stack overflow w D-Link DIR-600 via gena.cgi — zdalne wykonanie kodu