Clean up module
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
The module dlink_dir850_(un)auth_exec leverages an unauthenticated credential disclosure vulneralbility to then execute arbitrary commands via an authenticated OS command injection
|
||||
vulneralbility. D-LINK 850L (excluding "Cloud" models) devices with firmware version up to 1.14B07
|
||||
are potentially vulnerable. The vulneralbility seems to occur within the parsing of the config. Another PoC can be found here https://www.seebug.org/vuldb/ssvid-96333. Setting command to be `reboot` will force the router into an infinite loop.
|
||||
The module dlink_dir850_(un)auth_exec leverages an unauthenticated credential disclosure vulnerability to then execute arbitrary commands via an authenticated OS command injection
|
||||
vulnerability. D-LINK 850L (excluding "Cloud" models) devices with firmware version up to 1.14B07
|
||||
are potentially vulnerable. The vulnerability seems to occur within the parsing of the config. Another PoC can be found here https://www.seebug.org/vuldb/ssvid-96333. Setting command to be `reboot` will force the router into an infinite loop.
|
||||
|
||||
## Vulnerable Application
|
||||
|
||||
|
||||
Reference in New Issue
Block a user