CVE-2023-33625: Command Injection
Published Jun 12, 2023
·Updated
D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a command injection vulnerability via the ST parameter in the lxmldbcsystem() function.
Affected Software
4 affected components
Dlink Dir-600 Firmware=2.18
Dlink Dir-600=b5
All of the following
Dlink Dir-600 Firmware=2.18
Dlink Dir-600=b5
Event History
Jun 12, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this D-Link DIR-600 firmware?
The vulnerability ID for this D-Link DIR-600 firmware is CVE-2023-33625.
2
What is the severity of CVE-2023-33625?
The severity of CVE-2023-33625 is critical with a CVSS score of 9.8.
3
How does the command injection vulnerability occur in D-Link DIR-600 firmware?
The command injection vulnerability occurs due to improper handling of input in the ST parameter of the lxmldbc_system() function in the firmware.
4
Is D-Link DIR-600 Hardware Version B5 affected by this vulnerability?
No, D-Link DIR-600 Hardware Version B5 is not vulnerable to this command injection vulnerability.
5
How can I mitigate the CVE-2023-33625 vulnerability?
To mitigate the CVE-2023-33625 vulnerability, update the firmware for D-Link DIR-600 to a version that has the patch for this vulnerability.