D-Link DIR-890L 1.20b01 allows attackers to execute arbitrary code due to the hardcoded option Wake-On-Lan for the parameter 'descriptor' at SetVirtualServerSettings.php
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://www.dlink.com/en/security-bulletin/ | vendor advisory |
https://github.com/TyeYeah/DIR-890L-1.20-RCE | third party advisory exploit |