First published: Mon Jun 12 2023(Updated: )
D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a command injection vulnerability via the ST parameter in the lxmldbc_system() function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-600 Firmware | =2.18 | |
Dlink Dir-600 | =b5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this D-Link DIR-600 firmware is CVE-2023-33625.
The severity of CVE-2023-33625 is critical with a CVSS score of 9.8.
The command injection vulnerability occurs due to improper handling of input in the ST parameter of the lxmldbc_system() function in the firmware.
No, D-Link DIR-600 Hardware Version B5 is not vulnerable to this command injection vulnerability.
To mitigate the CVE-2023-33625 vulnerability, update the firmware for D-Link DIR-600 to a version that has the patch for this vulnerability.