ZDI-23-892: D-Link DIR-X3260 prog.cgi SOAPAction Command Injection Remote Code Execution Vulnerability
Published Jun 30, 2023
·Updated
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-X3260 routers. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
D-Link DIR-X3260
Event History
Jun 30, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
May 3, 2024
Advisory Published
via ZDI·02:09 AM
Frequently Asked Questions
1
What is the severity of ZDI-23-892?
The severity of ZDI-23-892 is critical due to the potential for remote arbitrary code execution.
2
Who is affected by the vulnerability ZDI-23-892?
D-Link DIR-X3260 routers are affected by the vulnerability ZDI-23-892.
3
How do I fix ZDI-23-892?
To fix ZDI-23-892, update your D-Link DIR-X3260 router firmware to the latest version provided by D-Link.
4
Is authentication required to exploit ZDI-23-892?
No, authentication is not required to exploit the vulnerability ZDI-23-892.
5
What type of attack does ZDI-23-892 enable?
ZDI-23-892 enables network-adjacent attackers to execute arbitrary code on the vulnerable D-Link routers.