ZDI-CAN-20553: ZDI-23-631: D-Link DIR-2150 SetNTPServerSettings Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2150 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-20553?
ZDI-CAN-20553 is considered a high severity vulnerability due to its potential for remote code execution.
How do I fix ZDI-CAN-20553?
To fix ZDI-CAN-20553, ensure that your D-Link DIR-2150 router is updated to the latest firmware version provided by D-Link.
Who is affected by ZDI-CAN-20553?
D-Link DIR-2150 router users are affected by ZDI-CAN-20553, especially those who have not updated their firmware.
Can ZDI-CAN-20553 be exploited remotely?
Yes, ZDI-CAN-20553 can be exploited by network-adjacent attackers, allowing the execution of arbitrary code.
Is authentication required to exploit ZDI-CAN-20553?
Yes, while authentication is required for exploiting ZDI-CAN-20553, the existing authentication mechanism can be bypassed.