CVE-2023-25280: D-Link DIR-820 Router OS Command Injection Vulnerability
D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafted payload with the pingaddr parameter to ping.ccp.
Other sources
OS Command injection vulnerability in D-Link DIR820LA1FW105B03 allows attackers to escalate privileges to root via a crafted payload with the pingaddr parameter to ping.ccp.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
D-Link DIR-820L Firmwarefrom your environment.Discontinue utilization of the product (end-of-life/end-of-service). Remove/decommission affected D-Link DIR-820L devices from service.
Event History
Frequently Asked Questions
What is the severity of CVE-2023-25280?
CVE-2023-25280 is considered a high severity vulnerability due to its potential for remote code execution and privilege escalation.
How do I fix CVE-2023-25280?
To fix CVE-2023-25280, users should update their D-Link DIR-820 router to the latest firmware version provided by D-Link.
Who is affected by CVE-2023-25280?
CVE-2023-25280 affects D-Link DIR-820 routers running firmware version 105b03.
What type of vulnerability is CVE-2023-25280?
CVE-2023-25280 is an OS command injection vulnerability that allows unauthenticated remote attackers to execute arbitrary commands.
What is the attack vector for CVE-2023-25280?
The attack vector for CVE-2023-25280 involves sending a crafted payload to the ping_addr parameter of the ping.ccp endpoint.