First published: Wed Jun 20 2018(Updated: )
On D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, OS command injection is possible as a result of incorrect processing of the res_buf parameter to index.cgi.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-link Dir-620 Firmware | =1.0.3 | |
D-link Dir-620 Firmware | =1.0.37 | |
D-link Dir-620 Firmware | =1.3.1 | |
D-link Dir-620 Firmware | =1.3.3 | |
D-link Dir-620 Firmware | =1.3.7 | |
D-link Dir-620 Firmware | =1.4.0 | |
D-link Dir-620 Firmware | =2.0.22 | |
Dlink Dir-620 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.