cbcvebase.
CVE-2023-24762
published 2023-03-13

CVE-2023-24762: OS Command injection vulnerability in D-Link DIR-867 DIR_867_FW1.30B07 allows attackers to execute arbitrary commands via a crafted LocalIPAddress parameter…

PriorityP265critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.62%
83.7th percentile
OS Command injection vulnerability in D-Link DIR-867 DIR_867_FW1.30B07 allows attackers to execute arbitrary commands via a crafted LocalIPAddress parameter for the SetVirtualServerSettings to HNAP1.

Affected

1 ranges
VendorProductVersion rangeFixed in
dlinkdir-867_firmware

Detection & IOCsextracted from sources · hover to see the quote

url/HNAP1
commandSetVirtualServerSettings
  • Monitor HTTP POST requests to /HNAP1 on D-Link DIR-867 devices targeting the SetVirtualServerSettings action with a malformed or shell-metacharacter-injected LocalIPAddress parameter, indicative of OS command injection exploitation.
  • GreyNoise observed active in-the-wild exploitation attempts tagged as 'D-Link CVE-2023-24762 RCE Attempt' during March 2023, indicating mass scanning/exploitation activity against this vulnerability.
  • ·Vulnerability is specific to D-Link DIR-867 firmware version DIR_867_FW1.30B07; detections should be scoped to this firmware version to reduce false positives.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.