First published: Thu Nov 17 2022(Updated: )
DLINK - DSL-224 Post-auth PCE. DLINK router has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will run with ROOT permissions on the router.
Credit: cna@cyber.gov.il cna@cyber.gov.il
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dsl-224 Firmware | ||
Dlink Dsl-224 |
Update to version 3.0.9_Beta Hotfix
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.