ZDI-23-625: D-Link DIR-2150 SetSysEmailSettings AccountName Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2150 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-625?
The severity of ZDI-23-625 is critical due to the ability of network-adjacent attackers to execute arbitrary code.
How do I fix ZDI-23-625?
To fix ZDI-23-625, update the firmware of D-Link DIR-2150 routers with the latest security patches from the manufacturer.
What type of attacks does ZDI-23-625 enable?
ZDI-23-625 enables network-adjacent attackers to bypass authentication and execute arbitrary code on affected devices.
Which devices are affected by ZDI-23-625?
ZDI-23-625 specifically affects D-Link DIR-2150 routers.
Is authentication required to exploit ZDI-23-625?
Yes, authentication is required to exploit ZDI-23-625, but the mechanism can be bypassed.