Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Vulnerabilities CVE-2023-25280

CVE-2023-25280

Medium
Open
KEV
TLP:CLEAR

D-Link DIR-820 Router OS Command Injection Vulnerability

NVD CVE.org
Critical Infrastructure

AI Analysis

No AI analysis yet.

Description

D-Link — DIR-820 Router — D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.

Details

EPSS Score
97.86%

99.9th percentile

Confidence
100%
CISA KEV
Date Added
Sep 30, 2024
Patch Due
Oct 21, 2024
Required Action
The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.