// For flags

CVE-2013-5945

D-Link DSR Router Series - Remote Command Execution

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 allow remote attackers to execute arbitrary SQL commands via the password to (1) the login.authenticate function in share/lua/5.1/teamf1lualib/login.lua or (2) captivePortal.lua.

Múltiples vulnerabilidades de inyección SQL en dispositivos D-Link DSR-150 con versión de firmware anterior a 1.08B44; DSR-150N con versiones de firmware anteriores a 1.05B64; DSR-250 y DSR-250N con versiones de firmware anteriores a 1.08B44; y DSR-500, DSR-500N, DSR-1000 y DSR-1000N con versiones de firmware anteriores a 1.08B77, permiten a atacantes remotos ejecutar comandos SQL arbitrarios por medio de la contraseña para (1) la función login.authenticate en los archivos share/lua/5.1/teamf1lualib/login.lua o (2) cautivePortal.lua.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-09-27 CVE Reserved
  • 2013-12-06 First Exploit
  • 2013-12-07 CVE Published
  • 2024-08-06 CVE Updated
  • 2024-10-08 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Dlink
Search vendor "Dlink"
Dsr-150 Firmware
Search vendor "Dlink" for product "Dsr-150 Firmware"
< 1.08b44
Search vendor "Dlink" for product "Dsr-150 Firmware" and version " < 1.08b44"
-
Affected
in Dlink
Search vendor "Dlink"
Dsr-150
Search vendor "Dlink" for product "Dsr-150"
--
Safe
Dlink
Search vendor "Dlink"
Dsr-150n Firmware
Search vendor "Dlink" for product "Dsr-150n Firmware"
< 1.05b64
Search vendor "Dlink" for product "Dsr-150n Firmware" and version " < 1.05b64"
-
Affected
in Dlink
Search vendor "Dlink"
Dsr-150n
Search vendor "Dlink" for product "Dsr-150n"
--
Safe
Dlink
Search vendor "Dlink"
Dsr-250 Firmware
Search vendor "Dlink" for product "Dsr-250 Firmware"
< 1.08b44
Search vendor "Dlink" for product "Dsr-250 Firmware" and version " < 1.08b44"
-
Affected
in Dlink
Search vendor "Dlink"
Dsr-250
Search vendor "Dlink" for product "Dsr-250"
--
Safe
Dlink
Search vendor "Dlink"
Dsr-250n Firmware
Search vendor "Dlink" for product "Dsr-250n Firmware"
< 1.08b44
Search vendor "Dlink" for product "Dsr-250n Firmware" and version " < 1.08b44"
-
Affected
in Dlink
Search vendor "Dlink"
Dsr-250n
Search vendor "Dlink" for product "Dsr-250n"
--
Safe
Dlink
Search vendor "Dlink"
Dsr-500 Firmware
Search vendor "Dlink" for product "Dsr-500 Firmware"
< 1.08b77
Search vendor "Dlink" for product "Dsr-500 Firmware" and version " < 1.08b77"
-
Affected
in Dlink
Search vendor "Dlink"
Dsr-500
Search vendor "Dlink" for product "Dsr-500"
--
Safe
Dlink
Search vendor "Dlink"
Dsr-500n Firmware
Search vendor "Dlink" for product "Dsr-500n Firmware"
< 1.08b77
Search vendor "Dlink" for product "Dsr-500n Firmware" and version " < 1.08b77"
-
Affected
in Dlink
Search vendor "Dlink"
Dsr-500n
Search vendor "Dlink" for product "Dsr-500n"
--
Safe
Dlink
Search vendor "Dlink"
Dsr-1000 Firmware
Search vendor "Dlink" for product "Dsr-1000 Firmware"
< 1.08b77
Search vendor "Dlink" for product "Dsr-1000 Firmware" and version " < 1.08b77"
-
Affected
in Dlink
Search vendor "Dlink"
Dsr-1000
Search vendor "Dlink" for product "Dsr-1000"
--
Safe
Dlink
Search vendor "Dlink"
Dsr-1000n Firmware
Search vendor "Dlink" for product "Dsr-1000n Firmware"
< 1.08b77
Search vendor "Dlink" for product "Dsr-1000n Firmware" and version " < 1.08b77"
-
Affected
in Dlink
Search vendor "Dlink"
Dsr-1000n
Search vendor "Dlink" for product "Dsr-1000n"
--
Safe