CVE-2013-10050: D-Link Devices tools_vct.xgi Authenticated RCE
An OS command injection vulnerability exists in multiple D-Link routers (confirmed on DIR-300 rev A v1.05 and DIR-615 rev D v4.13) via the authenticated toolsvct.xgi CGI endpoint. The web interface fails to properly sanitize user-supplied input in the pingIp parameter, allowing attackers with valid credentials to inject arbitrary shell commands. Exploitation enables full device compromise, including spawning a telnet daemon and establishing a root shell. The vulnerability is present in firmware versions that expose toolsvct.xgi and use the Mathopd/1.5p6 web server. No vendor patch is available, and affected models are end-of-life.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-10050?
CVE-2013-10050 has a medium severity level due to its potential for OS command injection in vulnerable routers.
Which devices are affected by CVE-2013-10050?
CVE-2013-10050 affects multiple D-Link routers, specifically the DIR-300 rev A and DIR-615 rev D.
How do I fix CVE-2013-10050?
To fix CVE-2013-10050, update the firmware of your affected D-Link router to the latest version provided by the manufacturer.
What type of vulnerability is CVE-2013-10050?
CVE-2013-10050 is classified as an OS command injection vulnerability.
What impact does CVE-2013-10050 have on my network security?
CVE-2013-10050 can lead to unauthorized command execution, compromising the integrity and confidentiality of your network.