ZDI-CAN-19548: ZDI-23-543: D-Link DIR-2640 DestNetwork Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2640 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-19548?
The severity of ZDI-CAN-19548 has been rated as high due to the potential for remote code execution.
How do I fix ZDI-CAN-19548?
To resolve ZDI-CAN-19548, users should update their D-Link DIR-2640 router firmware to the latest version.
What systems are vulnerable to ZDI-CAN-19548?
ZDI-CAN-19548 affects D-Link DIR-2640 routers with certain firmware versions.
Who can exploit ZDI-CAN-19548?
ZDI-CAN-19548 can be exploited by network-adjacent attackers with the capability to bypass the authentication mechanism.
What are the consequences of exploiting ZDI-CAN-19548?
Exploiting ZDI-CAN-19548 can allow attackers to execute arbitrary code on the affected D-Link routers.