CVE-2023-0127 is a command injection vulnerability affecting D-Link DWL-2600AP devices, specifically within the firmware_update command of its restricted Telnet interface. An authenticated, local attacker can leverage this flaw to execute arbitrary commands with root privileges, posing a high risk to system integrity, confidentiality, and availability. Despite its high severity CVSS score of 7.8, there is currently no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.2.0.17CPE matchmatch criteria | cpe:2.3:o:dlink:dwl-2600ap_firmware:4.2.0.17:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Command Injection in D-Link DWL-2600AP with firmware v4.2.0.17
Jan 9, 2023Command Injection in D-Link DWL-2600AP with firmware v4.2.0.17
Jan 9, 2023Command Injection in D-Link DWL-2600AP with firmware v4.2.0.17
Jan 9, 2023Command Injection in D-Link DWL-2600AP with firmware v4.2.0.17
Jan 9, 2023