ZDI-CAN-20558: ZDI-23-630: D-Link DIR-2150 GetDeviceSettings Target Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2150 routers. Authentication is not required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-20558?
ZDI-CAN-20558 is classified as a high severity vulnerability due to the potential for arbitrary code execution by network-adjacent attackers.
How do I fix ZDI-CAN-20558?
To fix ZDI-CAN-20558, update your D-Link DIR-2150 router to the latest firmware version provided by D-Link.
Who is affected by ZDI-CAN-20558?
ZDI-CAN-20558 affects users of D-Link DIR-2150 routers that have not applied the necessary security updates.
What types of attacks can exploit ZDI-CAN-20558?
ZDI-CAN-20558 can be exploited by network-adjacent attackers to execute arbitrary code on the affected routers.
Is authentication required to exploit ZDI-CAN-20558?
No, authentication is not required to exploit ZDI-CAN-20558, making it particularly critical.