CVE-2021-28144: OS Command Injection
prog.cgi on D-Link DIR-3060 devices before 1.11b04 HF2 allows remote authenticated users to inject arbitrary commands in an admin or root context because SetVirtualServerSettings calls CheckArpTables, which calls popen unsafely.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28144?
CVE-2021-28144 is considered a high-severity vulnerability as it allows remote authenticated users to perform command injection.
How do I fix CVE-2021-28144?
To mitigate CVE-2021-28144, users should upgrade to the latest firmware version provided by D-Link that addresses this vulnerability.
Who is affected by CVE-2021-28144?
CVE-2021-28144 affects D-Link DIR-3060 devices running firmware versions prior to 1.11b04 HF2.
What type of vulnerability is CVE-2021-28144?
CVE-2021-28144 is classified as a command injection vulnerability due to insecure handling of commands in the firmware.
Can CVE-2021-28144 be exploited remotely?
Yes, CVE-2021-28144 can be exploited remotely by authenticated users with access to the device's admin interface.