CVE-2021-27113: OS Command Injection
Published Apr 14, 2021
·Updated
An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/addRouting route. This could lead to Command Injection via Shell Metacharacters.
Affected Software
2 affected components
Dlink Dir-816 Firmware=1.10b05
Dlink DIR-816=a2
Event History
Apr 14, 2021
CVE Published
via MITRE·01:53 PM
Data Sourced
via MITRE·01:53 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2021-27113.
2
What is the severity of CVE-2021-27113?
The severity of CVE-2021-27113 is critical with a CVSS score of 9.8.
3
What is the affected software of CVE-2021-27113?
The affected software is D-Link DIR-816 A2 1.10 B05 devices.
4
What is the CWE-ID associated with CVE-2021-27113?
The CWE-ID associated with CVE-2021-27113 is CWE-77 and CWE-78.
5
How can the Command Injection via Shell Metacharacters be exploited in CVE-2021-27113?
The Command Injection via Shell Metacharacters can be exploited by constructing a malicious HTTP request parameter within the handler function of the /goform/addRouting route.