CVE-2023-31814: Critical severity d-link dir-300 firmware vulnerability
Published May 23, 2023
·Updated
D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/langmsg.php.
Affected Software
8 affected components
Dlink Dir-300 Firmware<=1.06
Dlink Dir-300=a
Dlink Dir-300 Firmware<=2.06
Dlink Dir-300=b
All of the following
Dlink Dir-300 Firmware<=1.06
Dlink Dir-300=a
All of the following
Dlink Dir-300 Firmware<=2.06
Dlink Dir-300=b
Event History
May 23, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-31814.
2
What is the severity of CVE-2023-31814?
The severity of CVE-2023-31814 is critical with a severity value of 9.8.
3
Which D-Link DIR-300 firmware versions are affected by CVE-2023-31814?
D-Link DIR-300 firmware versions REVA1.06 and REVB2.06 are affected by CVE-2023-31814.
4
How does CVE-2023-31814 exploit the vulnerability?
CVE-2023-31814 exploits the vulnerability through file inclusion via /model/__lang_msg.php.
5
Are there any official references or resources for CVE-2023-31814?
Yes, you can find official references and resources for CVE-2023-31814 at these links: [Reference 1](https://gist.github.com/1915504804/9503198d3cbd5bc7db47625ac0caaade), [Reference 2](https://www.dlink.com/en/security-bulletin/).