CVE-2013-5945: SQL Injection
Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 allow remote attackers to execute arbitrary SQL commands via the password to (1) the login.authenticate function in share/lua/5.1/teamf1lualib/login.lua or (2) captivePortal.lua.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5945?
The severity of CVE-2013-5945 is critical with a severity value of 9.8.
How can remote attackers exploit CVE-2013-5945?
Remote attackers can exploit CVE-2013-5945 to execute arbitrary SQL commands.
Which D-Link products are affected by CVE-2013-5945?
D-Link DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware versions before the specified ones are affected by CVE-2013-5945.
How can I fix the SQL injection vulnerabilities in D-Link DSR series?
To fix the SQL injection vulnerabilities, upgrade the firmware of D-Link DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500, DSR-500N, DSR-1000, and DSR-1000N to versions above the specified vulnerable ones.
Where can I find additional information about CVE-2013-5945?
Additional information about CVE-2013-5945 can be found in the provided references.