ZDI-CAN-20561: ZDI-23-633: D-Link DIR-2150 GetFirmwareStatus Target Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2150 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-20561?
ZDI-CAN-20561 is classified as a high severity vulnerability due to the potential for remote code execution.
How do I fix ZDI-CAN-20561?
To fix ZDI-CAN-20561, update the D-Link DIR-2150 router firmware to the latest version provided by D-Link.
What types of devices are affected by ZDI-CAN-20561?
ZDI-CAN-20561 affects D-Link DIR-2150 routers specifically.
Can ZDI-CAN-20561 be exploited remotely?
While ZDI-CAN-20561 requires authentication, the vulnerability can be exploited by adjacent network attackers.
What are the consequences of exploiting ZDI-CAN-20561?
Exploiting ZDI-CAN-20561 allows attackers to execute arbitrary code on the affected router, compromising its functionality and security.