ZDI-23-633: D-Link DIR-2150 GetFirmwareStatus Target Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2150 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-633?
The severity of ZDI-23-633 is considered critical due to the potential for arbitrary code execution.
How can I mitigate ZDI-23-633?
Mitigation for ZDI-23-633 involves applying the latest firmware updates from D-Link for the DIR-2150 router.
Who is affected by ZDI-23-633?
ZDI-23-633 affects users of the D-Link DIR-2150 router that can be exploited by network-adjacent attackers.
What kind of attacks are possible with ZDI-23-633?
ZDI-23-633 allows attackers to bypass authentication and execute arbitrary code on the router.
Is user interaction required for ZDI-23-633 exploitation?
Although authentication is required, the vulnerability can be exploited without user interaction as the authentication mechanism can be bypassed.