CVE-2023-45208 describes a critical command injection vulnerability in the D-Link DAP-X1860 repeater (firmware versions 1.00 through 1.01b05-01). An attacker within range can execute arbitrary shell commands as root during the setup process by crafting a malicious SSID, potentially leading to a denial of service if the SSID contains single quotes. With a CVSS score of 8.8 (High), this vulnerability presents a significant risk due to its low attack complexity (AV:A/AC:L) and high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered community attention with two mentions and media coverage, indicating awareness of its potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.00CPE matchmatch criteria | cpe:2.3:o:dlink:dap-1860_firmware:1.00:*:*:*:*:*:*:* | ||
1.01b05-01CPE matchmatch criteria | cpe:2.3:o:dlink:dap-1860_firmware:1.01b05-01:*:*:*:*:*:*:* | ||
1.01b94CPE matchmatch criteria | cpe:2.3:o:dlink:dap-1860_firmware:1.01b94:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.