First published: Tue Feb 11 2020(Updated: )
Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 allow remote attackers to execute arbitrary SQL commands via the password to (1) the login.authenticate function in share/lua/5.1/teamf1lualib/login.lua or (2) captivePortal.lua.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dsr-150 Firmware | <1.08b44 | |
Dlink Dsr-150 | ||
Dlink Dsr-150n Firmware | <1.05b64 | |
Dlink Dsr-150n | ||
Dlink Dsr-250 Firmware | <1.08b44 | |
Dlink Dsr-250 | ||
Dlink Dsr-250n Firmware | <1.08b44 | |
Dlink Dsr-250n | ||
Dlink Dsr-500 Firmware | <1.08b77 | |
Dlink Dsr-500 | ||
Dlink Dsr-500n Firmware | <1.08b77 | |
Dlink Dsr-500n | ||
Dlink Dsr-1000 Firmware | <1.08b77 | |
Dlink Dsr-1000 | ||
Dlink Dsr-1000n Firmware | <1.08b77 | |
Dlink Dsr-1000n |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-5945 is critical with a severity value of 9.8.
Remote attackers can exploit CVE-2013-5945 to execute arbitrary SQL commands.
D-Link DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware versions before the specified ones are affected by CVE-2013-5945.
To fix the SQL injection vulnerabilities, upgrade the firmware of D-Link DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500, DSR-500N, DSR-1000, and DSR-1000N to versions above the specified vulnerable ones.
Additional information about CVE-2013-5945 can be found in the provided references.