D-Link DAR-7000-40 Command Injection via resmanage.php (critical)
CVE-2024-4965 Published on May 16, 2024
D-Link DAR-7000-40 resmanage.php os command injection
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000-40 V31R02B1413C and classified as critical. This issue affects some unknown processing of the file /useratte/resmanage.php. The manipulation of the argument load leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264533 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
Timeline
Advisory disclosed
VulDB entry created
VulDB entry last update
Weakness Type
What is a Shell injection Vulnerability?
The software constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVE-2024-4965 has been classified to as a Shell injection vulnerability or weakness.
Products Associated with CVE-2024-4965
Want to know whenever a new CVE is published for D-Link Dar 7000 Firmware? stack.watch will email you.
Affected Versions
D-Link DAR-7000-40 Version V31R02B1413C is affected by CVE-2024-4965Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.