DLink DIR-610 Multiple Vulnerabilities

high Nessus Plugin ID 190370

Synopsis

A web application is affected by multiple vulnerabilities.

Description

The version of DLink installed on the remote host is unsupported and affected by multiple vulnerabilities as referenced in the vendor advisory.

- D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php

- D-Link DIR-610 devices allow Information Disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php

Note: These vulnerabilities only affect products that are no longer supported by the maintainer. Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

All consumers still using the product should immediately retire and replace the device.

See Also

http://www.nessus.org/u?243a769a

Plugin Details

Severity: High

ID: 190370

File Name: dlink_dir-610_cve-2020-9377.nasl

Version: 1.1

Type: remote

Family: Web Servers

Published: 2/9/2024

Updated: 2/11/2024

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.4

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2020-9377

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 8.2

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/h:dlink:dir

Required KB Items: installed_sw/DLink DIR

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/9/2020

Vulnerability Publication Date: 7/9/2020

CISA Known Exploited Vulnerability Due Dates: 4/15/2022

Reference Information

CVE: CVE-2020-9376, CVE-2020-9377