D-Link DIR-600 <=2.18 RCE via soapcgi_main
CVE-2024-7357 Published on August 1, 2024
D-Link DIR-600 soap.cgi soapcgi_main os command injection
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-600 up to 2.18. It has been rated as critical. This issue affects the function soapcgi_main of the file /soap.cgi. The manipulation of the argument service leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273329 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
Timeline
Advisory disclosed
VulDB entry created
VulDB entry last update
Weakness Type
What is a Shell injection Vulnerability?
The software constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVE-2024-7357 has been classified to as a Shell injection vulnerability or weakness.
Products Associated with CVE-2024-7357
Want to know whenever a new CVE is published for D-Link Dir 600 Firmware? stack.watch will email you.
Affected Versions
D-Link DIR-600:- Version 2.0 is affected.
- Version 2.1 is affected.
- Version 2.2 is affected.
- Version 2.3 is affected.
- Version 2.4 is affected.
- Version 2.5 is affected.
- Version 2.6 is affected.
- Version 2.7 is affected.
- Version 2.8 is affected.
- Version 2.9 is affected.
- Version 2.10 is affected.
- Version 2.11 is affected.
- Version 2.12 is affected.
- Version 2.13 is affected.
- Version 2.14 is affected.
- Version 2.15 is affected.
- Version 2.16 is affected.
- Version 2.17 is affected.
- Version 2.18 is affected.
- Version 2.0 is affected.
- Version 2.1 is affected.
- Version 2.2 is affected.
- Version 2.3 is affected.
- Version 2.4 is affected.
- Version 2.5 is affected.
- Version 2.6 is affected.
- Version 2.7 is affected.
- Version 2.8 is affected.
- Version 2.9 is affected.
- Version 2.10 is affected.
- Version 2.11 is affected.
- Version 2.12 is affected.
- Version 2.13 is affected.
- Version 2.14 is affected.
- Version 2.15 is affected.
- Version 2.16 is affected.
- Version 2.17 is affected.
- Version 2.18 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.