CVE-2013-10050 is an OS command injection vulnerability affecting multiple D-Link routers, including DIR-300 rev A and DIR-615 rev D, via the authenticated tools_vct.xgi CGI endpoint. It allows authenticated attackers to inject arbitrary shell commands due to improper input sanitization in the pingIp parameter. This vulnerability carries a CVSS score of 8.8 (High) and a FAUCET Risk Score of 99/100, indicating a severe risk of full device compromise, including root shell access. While not listed in CISA KEV, a Metasploit module exists for exploitation, and it has garnered significant community discussion. Affected models are end-of-life with no vendor patch available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.05CPE matchmatch criteria | cpe:2.3:o:dlink:dir-300_firmware:*:*:*:*:*:*:*:* | ||
<= 4.13CPE matchmatch criteria | cpe:2.3:o:dlink:dir-615_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.