t0ptop/D-Link-DIR-825

t0ptop/D-Link-DIR-825

Releases0
Stars5
D-Link DIR-825 have an unauthorized command injection vulnerability.

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH9 HIGH

In the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" parameters to execute arbitrary system commands after obtaining authorization.

9.8 CRITICAL7.5 HIGH

In the "webupg" binary of D-Link DIR-825 G1, attackers can bypass authentication through parameters "autoupgrade.asp", and perform functions such as downloading configuration files and updating firmware without authorization.