CRITICAL
D-Link Devices Unauthenticated RCE
Published Aug 5, 2025
10.0
CRITICALCVSS 4.0
EPSS 16.72%
Description
The web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an unauthenticated OS command injection vulnerability in command.php, which improperly handles the cmd POST parameter. A remote attacker can exploit this flaw without authentication to spawn a Telnet service on a specified port, enabling persistent interactive shell access as root.
Affected products
-
- Version 0StatusaffectedConstraints<=2.13
- Version
-
- Version 0StatusaffectedConstraints<=2.14b01
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| D-Link | DIR-300 rev B | unaffected |
| ||||||
| D-Link | DIR-600 rev B | unaffected |
|
Configuration 1
AND
- ≤ 2.14b01
Configuration 2
AND
- ≤ 2.13
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/auxiliary/admin/http/dlink_dir_300_600_exec_noauth.rb exploit
- https://web.archive.org/web/20150428184723/http://www.s3cur1ty.de/m1adv2013-003 technical-descriptionexploitThird Party Advisory
- https://www.exploit-db.com/exploits/24453 exploit
- https://www.vulncheck.com/advisories/dlink-devices-unauth-rce third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/auxiliary/admin/http/dlink_dir_300_600_exec_noauth.rb | exploit | |
| https://web.archive.org/web/20150428184723/http://www.s3cur1ty.de/m1adv2013-003 | technical-descriptionexploitThird Party Advisory | |
| https://www.exploit-db.com/exploits/24453 | exploit | |
| https://www.vulncheck.com/advisories/dlink-devices-unauth-rce | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 5, 2025
Updated May 15, 2026
Reserved Aug 5, 2025
Link CVE-2013-10069
CISA Vulnrichment
Updated Aug 6, 2025