Loading HuntDB...

D-Link DIR-820 Router OS Command Injection Vulnerability

Added Sept. 30, 2024 Due Oct. 21, 2024 CVE-2023-25280
Overdue D-Link / DIR-820 Router CWE-78

Description

D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.

Required Action

The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

References

Additional Information

Catalog Version
2025.01.24
Catalog Released
Jan. 24, 2025
Days Until Due
0 days
Last Updated
6 months, 2 weeks ago