D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Link | Tags |
---|---|
http://dlink.com | product |
https://www.dlink.com/en/security-bulletin/ | not applicable vendor advisory |
http://dir-820l.com | broken link |
https://github.com/skyedai910/Vuln/tree/master/DIR-820L/command_execution_0 | exploit third party advisory broken link |
https://github.com/zhizhuoshuma/cve_info_data/blob/ccaed4b94ba762eb8a8e003bfa762a7754b8182e/Vuln/Vuln/DIR-820L/command_execution_0/README.md | third party advisory exploit |