ID

VAR-202309-2231


CVE

CVE-2023-39637


DESCRIPTION

D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis.

Trust: 1.0

sources: NVD: CVE-2023-39637

AFFECTED PRODUCTS

vendor:dlinkmodel:dir-816scope:eqversion:1.10b05

Trust: 1.0

sources: NVD: CVE-2023-39637

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2023-39637
value: CRITICAL

Trust: 1.0

nvd@nist.gov: CVE-2023-39637
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

sources: NVD: CVE-2023-39637

PROBLEMTYPE DATA

problemtype:CWE-77

Trust: 1.0

sources: NVD: CVE-2023-39637

EXTERNAL IDS

db:NVDid:CVE-2023-39637

Trust: 1.0

sources: NVD: CVE-2023-39637

REFERENCES

url:http://d-link.com

Trust: 1.0

url:http://www.dlink.com.cn/techsupport/productinfo.aspx?m=dir-816

Trust: 1.0

url:https://github.com/mmmmmx1/dlink/blob/main/dir-816/readme.md

Trust: 1.0

url:https://www.dlink.com/en/security-bulletin/

Trust: 1.0

sources: NVD: CVE-2023-39637

SOURCES

db:NVDid:CVE-2023-39637

LAST UPDATE DATE

2024-08-14T15:15:46.898000+00:00


SOURCES UPDATE DATE

db:NVDid:CVE-2023-39637date:2023-09-13T17:37:22.413

SOURCES RELEASE DATE

db:NVDid:CVE-2023-39637date:2023-09-12T12:15:08.077