CVE-2024-57595: OS Command Injection
DLINK DIR-825 REVB 2.03 devices have an OS command injection vulnerability in the CGl interface apcclientpin.cgi, which allows remote attackers to execute arbitrary commands via the parameter "wpspin" passed to the apcclientpin.cgi binary through a POST request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-57595?
CVE-2024-57595 is classified as a high severity vulnerability due to its potential for remote command execution.
How do I fix CVE-2024-57595?
To fix CVE-2024-57595, update the D-Link DIR-825 to the latest firmware version provided by D-Link.
What does CVE-2024-57595 affect?
CVE-2024-57595 affects D-Link DIR-825 REV B2.03 devices.
Can CVE-2024-57595 be exploited remotely?
Yes, CVE-2024-57595 can be exploited remotely through crafted POST requests to the vulnerable CGI interface.
What is the nature of the vulnerability in CVE-2024-57595?
CVE-2024-57595 is an OS command injection vulnerability that allows attackers to execute arbitrary commands on the affected device.