CVE-2017-14429: OS Command Injection
The DHCP client on D-Link DIR-850L REV. A (with firmware through FW114WWb07h2abbeta1) and REV. B (with firmware through FW208WWb02) devices allows unauthenticated remote code execution as root because /etc/services/INET/inetipv4.php mishandles shell metacharacters, affecting generated files such as WAN-1-udhcpc.sh.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14429?
CVE-2017-14429 is classified as critical due to its potential for unauthenticated remote code execution as root.
How do I fix CVE-2017-14429?
To mitigate CVE-2017-14429, update the D-Link DIR-850L firmware to a version that is not affected by this vulnerability.
Which devices are affected by CVE-2017-14429?
CVE-2017-14429 affects D-Link DIR-850L REV. A with firmware through FW114WWb07_h2ab_beta1 and REV. B with firmware through FW208WWb02.
What impact does CVE-2017-14429 have on my D-Link DIR-850L router?
CVE-2017-14429 allows unauthenticated attackers to execute arbitrary code on your D-Link DIR-850L router, potentially compromising your device.
Is there a workaround for CVE-2017-14429 if I cannot update my firmware?
There is no official workaround for CVE-2017-14429; the only solution is to update to the latest firmware that addresses the vulnerability.