CVE-2023-4542
published 2023-08-25CVE-2023-4542: A vulnerability was found in D-Link DAR-8000-10 up to 20230809. It has been classified as critical. This affects an unknown part of the file /app/sys1.php. The…
PriorityP190critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
86.53%
99.7th percentile
A vulnerability was found in D-Link DAR-8000-10 up to 20230809. It has been classified as critical. This affects an unknown part of the file /app/sys1.php. The manipulation of the argument cmd with the input id leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-238047. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-link | dar-8000-10 | — | — |
| dlink | dar-8000-10_firmware | <= 2023-08-09 | — |
Detection & IOCsextracted from sources · hover to see the quote
yara↗
regex: uid=([0-9(a-z)]+) gid=([0-9(a-z)]+)
- →Look for POST requests to /app/sys1.php with a 'cmd' parameter containing OS command injection payloads (e.g., cmd=id). Successful exploitation returns output matching uid=...gid=... in the response body. ↗
- →Use FOFA queries 'body="DAR-8000-10" && title="D-Link"' or 'body="dar-8000-10" && title="d-link"' to identify exposed D-Link DAR-8000-10 devices on the internet. ↗
- →The vulnerability is unauthenticated and remotely exploitable (CVSS 9.8, EPSS 0.923 / 99.7th percentile). No authentication headers are required in the exploit HTTP request. ↗
- ·Affected firmware versions are only confirmed up to 20230809; devices running firmware dated after this may or may not be patched, as the vendor did not respond to disclosure. ↗
- ·The vendor was unresponsive to disclosure; no official patch confirmation exists. Treat all DAR-8000-10 firmware ≤ 20230809 as vulnerable. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vulncheck6.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-85cp-hm7f-pwxw: A vulnerability was found in D-Link DAR-8000-10 up to 20230809
ghsa_unreviewed·2023-08-26
CVE-2023-4542 [MEDIUM] CWE-78 GHSA-85cp-hm7f-pwxw: A vulnerability was found in D-Link DAR-8000-10 up to 20230809
A vulnerability was found in D-Link DAR-8000-10 up to 20230809. It has been classified as critical. This affects an unknown part of the file /app/sys1.php. The manipulation of the argument cmd with the input id leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-238047. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
VulnCheck
D-Link dar-8000-10_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
vulncheck·2023·CVSS 6.3
CVE-2023-4542 [MEDIUM] D-Link dar-8000-10_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
D-Link dar-8000-10_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
A vulnerability was found in D-Link DAR-8000-10 up to 20230809. It has been classified as critical. This affects an unknown part of the file /app/sys1.php. The manipulation of the argument cmd with the input id leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-238047. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected: D-Link dar-8000-10_firmware
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigat
No detection rules found.
Nuclei
D-Link DAR-8000-10 - Command Injection
nuclei·CVSS 9.8
CVE-2023-4542 [CRITICAL] D-Link DAR-8000-10 - Command Injection
D-Link DAR-8000-10 - Command Injection
D-Link DAR-8000-10 version has an operating system command injection vulnerability. The vulnerability originates from the parameter id of the file /app/sys1.php which can lead to operating system command injection.
Template:
id: CVE-2023-4542
info:
name: D-Link DAR-8000-10 - Command Injection
author: pussycat0x
severity: critical
description: |
D-Link DAR-8000-10 version has an operating system command injection vulnerability. The vulnerability originates from the parameter id of the file /app/sys1.php which can lead to operating system command injection.
impact: |
Unauthenticated attackers can execute arbitrary operating system commands through the id parameter in /app/sys1.php, potentially gaining full control of the D-Link DAR-8000-10 router an
Nuclei
CERIO-DT Interface - Command Execution
nuclei·CVSS 9.8
[CRITICAL] CERIO-DT Interface - Command Execution
CERIO-DT Interface - Command Execution
CERIO DT series routers have an operation command injection vulnerability in specific versions. An attacker could exploit this vulnerability to execute commands.
Template:
id: cerio-dt-rce
info:
name: CERIO-DT Interface - Command Execution
author: pussycat0x
severity: critical
description: |
CERIO DT series routers have an operation command injection vulnerability in specific versions. An attacker could exploit this vulnerability to execute commands.
reference:
- https://github.com/20142995/sectool
- https://github.com/tanjiti/sec_profile
- https://github.com/wy876/POC/blob/main/D-Link_DAR-8000%E6%93%8D%E4%BD%9C%E7%B3%BB%E7%BB%9F%E5%91%BD%E4%BB%A4%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E(CVE-2023-4542).md
classification:
cwe-id: CWE-78
metadata:
verifi
2023-08-25
Published
Exploited in the wild