Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetDynamicDNSSettings' functionality, where the 'ServerAddress' and 'Hostname' parameters in prog.cgi are stored in NVRAM and later used by rc to construct system commands executed via twsystem(). An attacker can exploit this vulnerability remotely without authentication by sending a specially crafted HTTP request, leading to arbitrary command execution on the device.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
D-Link DIR-878 安全漏洞
Vulnerability Description
D-Link DIR-878是中国友讯(D-Link)公司的一款无线路由器。 D-Link DIR-878 A1_FW101B04.bin版本存在安全漏洞,该漏洞源于SetDynamicDNSSettings功能中ServerAddress和Hostname参数未经验证,可能导致远程命令执行。
CVSS Information
N/A
Vulnerability Type
N/A