CVE-2025-60698

Lưu ý: Dữ liệu này chỉ có tính chất tham khảo, phục vụ nghiên cứu an ninh mạng.CyStack khuyến nghị người dùng không sử dụng các thông tin này nhằm các mục đích bất hợp pháp

Đang phân tích dữ liệu...

Giới thiệu chung

Dữ liệu gốc

A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the prog.cgi and rc binaries. The sub_432F60 function in prog.cgi stores user-supplied SetSysLogSettings/IPAddress values in NVRAM via nvram_safe_set("SysLogRemote_IPAddress", ...). These values are later retrieved in the sub_448DCC function of rc using nvram_safe_get and concatenated into a shell command executed via twsystem() without any sanitization. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the device through specially crafted HTTP requests to the router's web interface.

Sản phẩm và phạm vi ảnh hưởng

Đang phân tích dữ liệu...

Chi tiết kỹ thuật

Đang phân tích dữ liệu...

Khả năng khai thác

Đang phân tích dữ liệu...

Tác động kỹ thuật

Đang phân tích dữ liệu...

Tác động đến tổ chức

Đang phân tích dữ liệu...

Cách khắc phục

Đang phân tích dữ liệu...

Cách phát hiện

Đang phân tích dữ liệu...
Nguồn (7)
Tìm hiểu thêm

Kiểm tra chuyên sâu cùng giải pháp quản lý rủi ro Web toàn diện

Giải pháp CyStack VulnScan liên tục phát hiện tài sản, xác minh lỗ hổng và giúp đội ngũ bảo mật ưu tiên khắc phục cho toàn bộ doanh nghiệp.

Khám phá CyStack VulnScan