CVE-2013-10069
D-Link Devices Unauthenticated RCE
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
The web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an unauthenticated OS command injection vulnerability in command.php, which improperly handles the cmd POST parameter. A remote attacker can exploit this flaw without authentication to spawn a Telnet service on a specified port, enabling persistent interactive shell access as root.
La interfaz web de varios routers D-Link, incluyendo el DIR-600 rev B (?2.14b01) y el DIR-300 rev B (?2.13), contiene una vulnerabilidad de inyección de comandos del sistema operativo no autenticados en command.php, que gestiona incorrectamente el parámetro POST cmd. Un atacante remoto puede explotar esta vulnerabilidad sin autenticación para generar un servicio Telnet en un puerto específico, lo que permite el acceso persistente al shell interactivo como root.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2025-08-05 CVE Reserved
- 2025-08-05 CVE Published
- 2025-08-06 CVE Updated
- 2025-08-06 First Exploit
- 2025-08-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
- CAPEC-88: OS Command Injection
References (4)
URL | Tag | Source |
---|---|---|
https://www.vulncheck.com/advisories/dlink-devices-unauth-rce | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
D-Link Search vendor "D-Link" | DIR-600 Rev B Search vendor "D-Link" for product "DIR-600 Rev B" | <= 2.14b01 Search vendor "D-Link" for product "DIR-600 Rev B" and version " <= 2.14b01" | en |
Affected
| ||||||
D-Link Search vendor "D-Link" | DIR-300 Rev B Search vendor "D-Link" for product "DIR-300 Rev B" | <= 2.13 Search vendor "D-Link" for product "DIR-300 Rev B" and version " <= 2.13" | en |
Affected
|