D-Link DAR-8000是中国友讯(D-Link)公司的上网行为审计网关。 D-Link DAR-8000-10版本存在操作系统命令注入漏洞,该漏洞源于文件/app/sys1.php的参数id会导致操作系统命令注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| D-Link | DAR-8000-10 | 20230809 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/PumpkinBridge/CVE-2023-4542 | POC Details |
| 2 | CERIO DT series routers have an operation command injection vulnerability in specific versions. An attacker could exploit this vulnerability to execute commands. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/other/cerio-dt-rce.yaml | POC Details |
| 3 | D-Link DAR-8000-10 version has an operating system command injection vulnerability. The vulnerability originates from the parameter id of the file /app/sys1.php which can lead to operating system command injection. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-4542.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet