CVE-2023-39637: Command Injection
Published Sep 12, 2023
·Updated
D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis.
Affected Software
4 affected components
Dlink Dir-816 Firmware=1.10b05
Dlink DIR-816=a2
All of the following
Dlink Dir-816 Firmware=1.10b05
Dlink DIR-816=a2
Event History
Sep 12, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-39637?
The severity of CVE-2023-39637 is critical with a score of 9.8.
2
How does CVE-2023-39637 affect D-Link DIR-816 A2 firmware version 1.10 B05?
CVE-2023-39637 affects D-Link DIR-816 A2 firmware version 1.10 B05 by allowing command injection through the component /goform/Diagnosis.
3
Is D-Link DIR-816 A2 firmware version a2 vulnerable to CVE-2023-39637?
No, D-Link DIR-816 A2 firmware version a2 is not vulnerable to CVE-2023-39637.
4
How can I fix the command injection vulnerability in D-Link DIR-816 A2 firmware version 1.10 B05?
To fix the command injection vulnerability in D-Link DIR-816 A2 firmware version 1.10 B05, you should update to the latest firmware version provided by D-Link.
5
Where can I find more information about CVE-2023-39637?
You can find more information about CVE-2023-39637 on the D-Link official website, the D-Link China tech support page, and the GitHub repository mentioned in the references section.