CVE-2013-10059 is an authenticated OS command injection vulnerability affecting various D-Link routers, specifically tested on the DIR-615H1 running firmware version 8.04. The vulnerability stems from insufficient input sanitization in the tools_vct.htm diagnostic interface, allowing attackers to inject arbitrary shell commands via the ping_ipaddr parameter. This high-severity flaw (CVSS 7.2) permits remote attackers, with default credentials, to achieve full compromise of the device, including confidentiality, integrity, and availability. While not on the CISA KEV catalog, a Metasploit module exists for this vulnerability, and it garners significant community discussion, indicating active awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.04CPE matchmatch criteria | cpe:2.3:o:dlink:dir-615h_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.