CVE-2023-32165
published 2024-05-03CVE-2023-32165: D-Link D-View TftpReceiveFileHandler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary…
PriorityP185critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
73.31%
99.4th percentile
D-Link D-View TftpReceiveFileHandler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the TftpReceiveFileHandler class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-19497.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-link | d-view | — | — |
| dlink | d-view_8 | <= 2.0.1.27 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability exists within the TftpReceiveFileHandler class of D-Link D-View; monitor for TFTP-based file upload requests that contain directory traversal sequences (e.g., '../') in the supplied path, which may indicate exploitation attempts targeting this handler. ↗
- →No authentication is required to exploit this vulnerability; any unauthenticated TFTP request to D-Link D-View containing path traversal patterns should be treated as suspicious and investigated. ↗
- →Successful exploitation results in code execution as SYSTEM; monitor for unexpected SYSTEM-level process creation originating from D-View service processes following TFTP activity. ↗
- ·The vulnerability affects D-Link D-View 8 (network management suite); D-Link has released a fix — ensure patched versions are deployed to remediate the risk. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
2024-05-03
Published