ZDI-23-630: D-Link DIR-2150 GetDeviceSettings Target Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2150 routers. Authentication is not required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-630?
The severity of ZDI-23-630 is considered critical due to the potential for arbitrary code execution without authentication.
How do I fix ZDI-23-630?
To fix ZDI-23-630, users should update their D-Link DIR-2150 routers to the latest firmware version provided by the manufacturer.
Who is affected by ZDI-23-630?
Individuals using D-Link DIR-2150 routers are affected by ZDI-23-630 vulnerability.
Can ZDI-23-630 be exploited remotely?
Yes, ZDI-23-630 can be exploited by network-adjacent attackers, indicating it does not require any special authentication.
What are the potential consequences of ZDI-23-630?
The consequences of ZDI-23-630 include the risk of arbitrary code execution, which could lead to complete system compromise.