CVE-2013-5945 describes multiple critical SQL injection vulnerabilities in several D-Link DSR series routers, including the DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500, DSR-500N, DSR-1000, and DSR-1000N, with specific firmware versions prior to their respective patches. These flaws allow remote, unauthenticated attackers to execute arbitrary SQL commands by injecting malicious input into the password field of the login.authenticate or captivePortal.lua functions. The vulnerability carries a CVSS v3.1 score of 9.8 (Critical), indicating a severe risk due to its network-based attack vector, low attack complexity, and no required user interaction or privileges, leading to complete compromise of confidentiality, integrity, and availability. Its high FAUCET Risk Score of 97/100 further emphasizes the significant danger it poses. While not listed on the CISA KEV catalog, an ExploitDB entry (EDB-30062) exists for Remote Command Execution, suggesting public exploit code availability. The CVE has garnered significant community discussion with 10 mentions, indicating awareness and potential interest in its exploitation, despite no reported active exploitation or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.08b44CPE matchmatch criteria | cpe:2.3:o:dlink:dsr-150_firmware:*:*:*:*:*:*:*:* | ||
< 1.05b64CPE matchmatch criteria | cpe:2.3:o:dlink:dsr-150n_firmware:*:*:*:*:*:*:*:* | ||
< 1.08b44CPE matchmatch criteria | cpe:2.3:o:dlink:dsr-250_firmware:*:*:*:*:*:*:*:* | ||
< 1.08b44CPE matchmatch criteria | cpe:2.3:o:dlink:dsr-250n_firmware:*:*:*:*:*:*:*:* | ||
< 1.08b77CPE matchmatch criteria | cpe:2.3:o:dlink:dsr-500_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.