CVE-2013-5946: OS Command Injection
The runShellCmd function in systemCheck.htm in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) "Ping or Trace an IP Address" or (2) "Perform a DNS Lookup" section.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5946?
CVE-2013-5946 has been rated as a high severity vulnerability due to its potential for remote code execution via unauthenticated attackers.
How do I fix CVE-2013-5946?
To fix CVE-2013-5946, users should upgrade their D-Link devices to firmware version 1.08B77 or later for DSR series and corresponding fixed versions for affected models.
Which D-Link models are affected by CVE-2013-5946?
CVE-2013-5946 affects D-Link DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500, DSR-500N, DSR-1000, and DSR-1000N models running outdated firmware.
Can CVE-2013-5946 be exploited remotely?
Yes, CVE-2013-5946 can be exploited remotely by attackers without authentication.
What is the nature of the vulnerability in CVE-2013-5946?
CVE-2013-5946 allows remote attackers to execute arbitrary commands on affected D-Link devices.