DLINK DIR-825 REVB 2.03 devices have an OS command injection vulnerability in the CGl interface apc_client_pin.cgi, which allows remote attackers to execute arbitrary commands via the parameter "wps_pin" passed to the apc_client_pin.cgi binary through a POST request.
Metrics
Affected Vendors & Products
References
History
Mon, 27 Jan 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-78 | |
Metrics |
cvssV3_1
|
Mon, 27 Jan 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | DLINK DIR-825 REVB 2.03 devices have an OS command injection vulnerability in the CGl interface apc_client_pin.cgi, which allows remote attackers to execute arbitrary commands via the parameter "wps_pin" passed to the apc_client_pin.cgi binary through a POST request. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-01-27T00:00:00.000Z
Updated: 2025-01-27T15:32:01.410Z
Reserved: 2025-01-09T00:00:00.000Z
Link: CVE-2024-57595

Updated: 2025-01-27T15:30:17.376Z

Status : Received
Published: 2025-01-27T15:15:11.580
Modified: 2025-01-27T16:15:31.613
Link: CVE-2024-57595

No data.