cbcvebase.
CVE-2023-33625
published 2023-06-12

CVE-2023-33625: D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a command injection vulnerability via the ST parameter in the…

PriorityP180critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
33.15%
98.2th percentile
D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a command injection vulnerability via the ST parameter in the lxmldbc_system() function.

Affected

1 ranges
VendorProductVersion rangeFixed in
dlinkdir-600_firmware

Detection & IOCsextracted from sources · hover to see the quote

port1900
commandM-SEARCH (SSDP ST field injection)
  • Monitor UDP port 1900 for crafted M-SEARCH packets where the ST (Search Target) field contains shell metacharacters or command injection payloads targeting D-Link UPnP services.
  • The exploitation results in a root-level shell; look for unexpected outbound connections or process spawning from the UPnP daemon (lxmldbc_system) on affected D-Link devices.
  • The vulnerable code path is the lxmldbc_system() function processing the ST parameter — focus network/host inspection on UPnP M-SEARCH traffic to DIR-600 B5 fw 2.18 and related models.
  • ·Staged Meterpreter payloads may crash the target device; stageless payloads should be used when testing with the Linux Dropper target.
  • ·Some affected D-Link devices lack the `wget` binary; the echo cmdstager flavor must be used as a fallback for payload delivery.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.