ZDI-CAN-20559: ZDI-23-629: D-Link DIR-2150 SetSysEmailSettings EmailTo Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2150 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-20559?
ZDI-CAN-20559 has been classified as a critical vulnerability due to its ability to allow arbitrary code execution.
How do I fix ZDI-CAN-20559?
To fix ZDI-CAN-20559, update your D-Link DIR-2150 router to the latest firmware version provided by D-Link.
Who is affected by ZDI-CAN-20559?
ZDI-CAN-20559 specifically affects installations of D-Link DIR-2150 routers that have the vulnerability present.
What types of attacks can ZDI-CAN-20559 facilitate?
ZDI-CAN-20559 can facilitate network-adjacent attackers to execute arbitrary code on the affected routers.
Is authentication enough to protect against ZDI-CAN-20559?
No, the existing authentication mechanism can be bypassed, making it insufficient to protect against ZDI-CAN-20559.