
t0ptop/D-Link-DIR-825
Releases0
Stars5
D-Link DIR-825 have an unauthorized command injection vulnerability.
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 8.8 HIGH | 9 HIGH | ||
In the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" parameters to execute arbitrary system commands after obtaining authorization. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
In the "webupg" binary of D-Link DIR-825 G1, attackers can bypass authentication through parameters "autoupgrade.asp", and perform functions such as downloading configuration files and updating firmware without authorization. | |||