ZDI-CAN-20983: ZDI-23-892: D-Link DIR-X3260 prog.cgi SOAPAction Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-X3260 routers. Authentication is not required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-20983?
The severity of ZDI-CAN-20983 is considered high due to its potential for arbitrary code execution by unauthenticated attackers.
How do I fix ZDI-CAN-20983?
To fix ZDI-CAN-20983, you should immediately update the firmware of your D-Link DIR-X3260 router to the latest version provided by the manufacturer.
Who is affected by ZDI-CAN-20983?
ZDI-CAN-20983 affects installations of D-Link DIR-X3260 routers that have not been updated to the latest firmware.
Can ZDI-CAN-20983 be exploited remotely?
Yes, ZDI-CAN-20983 can be exploited by network-adjacent attackers, meaning they need to be on the same local network.
What type of vulnerability is ZDI-CAN-20983?
ZDI-CAN-20983 is a code execution vulnerability that allows attackers to execute arbitrary code without authentication.