ZDI-23-626: D-Link DIR-2150 SetSysEmailSettings EmailFrom Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2150 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-626?
The severity of ZDI-23-626 is critical due to its potential to allow remote code execution.
How do I fix ZDI-23-626?
To fix ZDI-23-626, update your D-Link DIR-2150 router to the latest firmware version released by D-Link.
Who is affected by ZDI-23-626?
ZDI-23-626 affects users of D-Link DIR-2150 routers with a specific vulnerability in their authentication mechanism.
Can ZDI-23-626 be exploited remotely?
Yes, ZDI-23-626 can be exploited remotely, but it requires bypassing the existing authentication mechanism.
What do I need to mitigate ZDI-23-626?
To mitigate ZDI-23-626, it is essential to apply the necessary firmware updates and strengthen router security settings.