CVE-2013-10069 describes an unauthenticated OS command injection vulnerability in the web interface of several D-Link routers, including DIR-600 rev B and DIR-300 rev B, specifically within the command.php script's handling of the 'cmd' POST parameter. This critical flaw (CVSS 9.8) allows a remote attacker to execute arbitrary commands without authentication, enabling them to spawn a Telnet service for persistent root-level shell access. While not listed in CISA KEV, a Metasploit module exists for exploitation, indicating readily available exploit code, though there is minimal community discussion or media coverage surrounding this older vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.14b01CPE matchmatch criteria | cpe:2.3:o:dlink:dir-600_firmware:*:*:*:*:*:*:*:* | ||
<= 2.13CPE matchmatch criteria | cpe:2.3:o:dlink:dir-300_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.