CVE-2023-5146: D-Link DAR-7000/DAR-8000 updatelib.php unrestricted upload
UNSUPPORTED WHEN ASSIGNED A vulnerability was found in D-Link DAR-7000 and DAR-8000 up to 20151231 and classified as critical. Affected by this issue is some unknown functionality of the file /sysmanage/updatelib.php. The manipulation of the argument fileupload leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-240242 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-5146?
CVE-2023-5146 is a critical vulnerability found in D-Link DAR-7000 and DAR-8000 up to 20151231.
What is the severity of CVE-2023-5146?
CVE-2023-5146 has a severity rating of 8.8 (high).
Which software is affected by CVE-2023-5146?
The affected software are D-Link DAR-7000 and DAR-8000 up to 20151231.
How can I fix CVE-2023-5146?
To fix CVE-2023-5146, it is recommended to update the firmware of D-Link DAR-7000 and DAR-8000 to a version beyond 20151231.
Where can I find more information about CVE-2023-5146?
You can find more information about CVE-2023-5146 at the following references: [Reference 1](https://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_upload_%20updatelib.md), [Reference 2](https://github.com/llixixi/cve/blob/main/D-LINK-DAR-8000-10_upload_%20updatelib.md), [Reference 3](https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10354).