CVE-2023-50203: D-Link G416 nodered chmod Command Injection Remote Code Execution Vulnerability
D-Link G416 nodered chmod Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link G416 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the HTTP service listening on TCP port 80. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-21296.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50203?
CVE-2023-50203 is classified as a critical severity vulnerability.
How do I fix CVE-2023-50203?
To address CVE-2023-50203, users should update their D-Link G416 routers to the latest firmware provided by D-Link.
Who is affected by CVE-2023-50203?
CVE-2023-50203 affects all installations of D-Link G416 routers that have not been patched.
Can CVE-2023-50203 be exploited remotely?
Yes, CVE-2023-50203 can be exploited remotely by network-adjacent attackers without requiring authentication.
What can attackers do with CVE-2023-50203?
Attackers exploiting CVE-2023-50203 can execute arbitrary code on affected D-Link G416 routers.