Severity
5.3MEDIUM
EPSS
1.1%
top 22.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 10

Description

A vulnerability was found in D-Link DI-8003 16.07.16A1. It has been classified as critical. Affected is the function upgrade_filter_asp of the file /upgrade_filter.asp. The manipulation of the argument path leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5d-link/di-800316.07.16A1
NVDdlink/di-8003_firmware16.07.16a1

🔴Vulnerability Details

2
GHSA
GHSA-cvj9-g4h2-mvqx: A vulnerability was found in D-Link DI-8003 162024-11-10
CVEList
D-Link DI-8003 upgrade_filter.asp upgrade_filter_asp os command injection2024-11-10