First published: Sun Mar 27 2022(Updated: )
In DLink DAP-1360 F1 firmware version <=v6.10 in the "webupg" binary, an attacker can use the "file" parameter to execute arbitrary system commands when the parameter is "name=deleteFile" after being authorized.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dap-1360f1 Firmware | <=6.10 | |
DLink DAP-1360 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.