CVE-2023-31814
published 2023-05-23CVE-2023-31814: D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.
PriorityP347critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.89%
55.0th percentile
D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlink | dir-300_firmware | <= 1.06 | — |
| dlink | dir-300_firmware | <= 2.06 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET EXPLOIT pfBlockerNG HTTP Host Header Remote Code Execution Attempt (CVE-2022-31814)
suricata·2023-03-15·CVSS 9.8
CVE-2022-31814 [CRITICAL] ET EXPLOIT pfBlockerNG HTTP Host Header Remote Code Execution Attempt (CVE-2022-31814)
ET EXPLOIT pfBlockerNG HTTP Host Header Remote Code Execution Attempt (CVE-2022-31814)
Rule: alert http any any -> [$HTTP_SERVERS,$HOME_NET] any (msg:"ET EXPLOIT pfBlockerNG HTTP Host Header Remote Code Execution Attempt (CVE-2022-31814)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/pfblockerng/www/index.php"; fast_pattern; http.host; content:"|2a 3b|"; startswith; reference:url,www.ihteam.net/advisory/pfblockerng-unauth-rce-vulnerability/; reference:cve,2022-31814; classtype:attempted-admin; sid:2044629; rev:1; metadata:affected_product IoT, attack_target Networking_Equipment, created_at 2023_03_15, cve CVE_2022_31814, deployment Perimeter, deployment Internal, deployment SSLDecrypt, performance_impact Low, confidence High, signature_severity Major, tag De
No public exploits indexed.
No writeups or analysis indexed.
2023-05-23
Published