CRITICAL🇵🇱 Wersja polska

CVE-2013-10048

CVSS 9.3v4.0pub. 2025-08-01upd. 2025-09-23

An OS command injection vulnerability exists in various legacy D-Link routers—including DIR-300 rev B and DIR-600 (firmware ≤ 2.13 and ≤ 2.14b01, respectively)—due to improper input handling in the unauthenticated command.php endpoint. By sending specially crafted POST requests, a remote attacker can execute arbitrary shell commands with root privileges, allowing full takeover of the device. This includes launching services such as Telnet, exfiltrating credentials, modifying system configuration, and disrupting availability. The flaw stems from the lack of authentication and inadequate sanitation of the cmd parameter.

🤖 AI Analysis
How it works

The command.php endpoint accepts HTTP POST requests without any authentication mechanism. The cmd parameter passed in the request body is not properly sanitized, which allows an attacker to inject arbitrary system commands. These commands are executed directly by the device's operating system with root privileges. It is sufficient to send a crafted POST request over the network, without the need to possess any login credentials.

Impact

The attacker gains full control of the device with root privileges, which enables launching services such as Telnet, stealing authentication credentials, modifying system configuration, and disrupting device availability.

Mitigation & patch

Apply patches available from the manufacturer according to the references. Due to the legacy status of the devices, it is recommended to verify firmware update availability from the manufacturer, and in case of unavailability — isolate the devices from the public Internet and restrict access to the management interface exclusively to trusted hosts on the local network. Consider replacing the devices with current models supported by the manufacturer.

Who is affected

D-Link DIR-300 rev B and D-Link DIR-600 with firmware version ≤ 2.13 (DIR-300) and ≤ 2.14b01 (DIR-600)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Dlink Dir 300

    HW
    Dlink
    all versions
  • Dlink Dir 300 Firmware

    OS
    Dlink
    ≤ 2.13
  • Dlink Dir 600

    HW
    Dlink
    all versions
  • Dlink Dir 600 Firmware

    OS
    Dlink
    ≤ 2.14b01
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2018-25115CRITICAL10.0PL ✓same product

D-Link DIR-series — nieuwierzytelniony command injection w service.cgi (root RCE)

CVE-2013-10069CRITICAL10.0PL ✓same product

D-Link DIR-300/DIR-600 — nieuwierzytelniony OS command injection w command.php

CVE-2024-41616CRITICAL9.8PL ✓same product

D-Link DIR-300: zakodowane na stałe dane uwierzytelniające w usłudze Telnet

CVE-2023-33625CRITICAL9.8PL ✓same product

Command injection w routerze D-Link DIR-600 via parametr ST

CVE-2023-33626CRITICAL9.8PL ✓same product

Stack overflow w D-Link DIR-600 via gena.cgi — zdalne wykonanie kodu