First published: Sat Jul 06 2019(Updated: )
An issue was discovered in the D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6. Input does not get validated and arbitrary SQL statements can be executed in the database via the /web/Public/Conn.php parameter dbSQL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Central Wifimanager | =1.03 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-13373.
The affected software is D-Link Central WiFi Manager (CWM) version 1.03.
The severity level of CVE-2019-13373 is critical with a severity score of 9.8.
This vulnerability can be exploited by sending arbitrary SQL statements via the /web/Public/Conn.php parameter dbSQL, allowing unauthorized execution of database queries.
At the moment, there is no known fix for CVE-2019-13373. It is recommended to follow the vendor's security advisory for updates and mitigation steps.