CVE-2021-28144

prog.cgi on D-Link DIR-3060 devices before 1.11b04 HF2 allows remote authenticated users to inject arbitrary commands in an admin or root context because SetVirtualServerSettings calls CheckArpTables, which calls popen unsafely.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dlink:dir-3060_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-3060:-:*:*:*:*:*:*:*

Information

Published : 2021-03-11 09:15

Updated : 2021-04-23 07:46


NVD link : CVE-2021-28144

Mitre link : CVE-2021-28144


JSON object : View

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

Advertisement

dedicated server usa

Products Affected

dlink

  • dir-3060_firmware
  • dir-3060