D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.
The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.
Link | Tags |
---|---|
https://www.dlink.com/en/security-bulletin/ | product |
https://gist.github.com/1915504804/9503198d3cbd5bc7db47625ac0caaade | third party advisory |