ZDI-23-545: D-Link DIR-2640 EmailFrom Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2640 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-545?
The severity of ZDI-23-545 is critical due to the potential for arbitrary code execution on affected devices.
How do I fix ZDI-23-545?
To fix ZDI-23-545, ensure that you update your D-Link DIR-2640 router firmware to the latest version provided by the vendor.
Who is affected by ZDI-23-545?
ZDI-23-545 affects installations of the D-Link DIR-2640 router and its firmware.
Can ZDI-23-545 be exploited without authentication?
No, ZDI-23-545 requires authentication; however, the existing authentication mechanism can be bypassed by attackers.
What type of vulnerability is ZDI-23-545?
ZDI-23-545 is classified as a remote code execution vulnerability that allows attackers to execute arbitrary code.