Vulnerability Details CVE-2013-5945
Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 allow remote attackers to execute arbitrary SQL commands via the password to (1) the login.authenticate function in share/lua/5.1/teamf1lualib/login.lua or (2) captivePortal.lua.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.083
EPSS Ranking 91.8%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 10.0
Products affected by CVE-2013-5945
-
cpe:2.3:h:dlink:dsr-1000:-
-
cpe:2.3:h:dlink:dsr-1000n:-
-
cpe:2.3:h:dlink:dsr-150:-
-
cpe:2.3:h:dlink:dsr-150n:-
-
cpe:2.3:h:dlink:dsr-250:-
-
cpe:2.3:h:dlink:dsr-250n:-
-
cpe:2.3:h:dlink:dsr-500:-
-
cpe:2.3:h:dlink:dsr-500n:-
-
cpe:2.3:o:dlink:dsr-1000_firmware:1.01b50
-
cpe:2.3:o:dlink:dsr-1000_firmware:1.02b11
-
cpe:2.3:o:dlink:dsr-1000_firmware:1.02b25
-
cpe:2.3:o:dlink:dsr-1000_firmware:1.03b12
-
cpe:2.3:o:dlink:dsr-1000_firmware:1.03b23
-
cpe:2.3:o:dlink:dsr-1000_firmware:1.03b27
-
cpe:2.3:o:dlink:dsr-1000_firmware:1.03b36
-
cpe:2.3:o:dlink:dsr-1000_firmware:1.03b43
-
cpe:2.3:o:dlink:dsr-1000_firmware:1.04b58
-
cpe:2.3:o:dlink:dsr-1000_firmware:1.06b43
-
cpe:2.3:o:dlink:dsr-1000_firmware:1.06b53
-
cpe:2.3:o:dlink:dsr-1000n_firmware:1.01b50
-
cpe:2.3:o:dlink:dsr-1000n_firmware:1.02b11
-
cpe:2.3:o:dlink:dsr-1000n_firmware:1.02b25
-
cpe:2.3:o:dlink:dsr-1000n_firmware:1.03b12
-
cpe:2.3:o:dlink:dsr-1000n_firmware:1.03b23
-
cpe:2.3:o:dlink:dsr-1000n_firmware:1.03b27
-
cpe:2.3:o:dlink:dsr-1000n_firmware:1.03b36
-
cpe:2.3:o:dlink:dsr-1000n_firmware:1.03b43
-
cpe:2.3:o:dlink:dsr-1000n_firmware:1.04b58
-
cpe:2.3:o:dlink:dsr-1000n_firmware:1.06b43
-
cpe:2.3:o:dlink:dsr-1000n_firmware:1.06b53
-
cpe:2.3:o:dlink:dsr-1000n_firmware:1.08b51
-
cpe:2.3:o:dlink:dsr-150_firmware:1.0.9b32
-
cpe:2.3:o:dlink:dsr-150_firmware:1.05b29
-
cpe:2.3:o:dlink:dsr-150_firmware:1.05b35
-
cpe:2.3:o:dlink:dsr-150_firmware:1.05b46
-
cpe:2.3:o:dlink:dsr-150_firmware:1.05b50
-
cpe:2.3:o:dlink:dsr-150_firmware:1.08
-
cpe:2.3:o:dlink:dsr-150_firmware:1.08b29
-
cpe:2.3:o:dlink:dsr-150n_firmware:1.05b48
-
cpe:2.3:o:dlink:dsr-250_firmware:1.01b46
-
cpe:2.3:o:dlink:dsr-250_firmware:1.01b56
-
cpe:2.3:o:dlink:dsr-250_firmware:1.05b20
-
cpe:2.3:o:dlink:dsr-250_firmware:1.05b53
-
cpe:2.3:o:dlink:dsr-250_firmware:1.08b31
-
cpe:2.3:o:dlink:dsr-250_firmware:1.08b39
-
cpe:2.3:o:dlink:dsr-250n_firmware:1.01b46
-
cpe:2.3:o:dlink:dsr-250n_firmware:1.01b56
-
cpe:2.3:o:dlink:dsr-250n_firmware:1.05b20
-
cpe:2.3:o:dlink:dsr-250n_firmware:1.05b53
-
cpe:2.3:o:dlink:dsr-250n_firmware:1.05b73_ww
-
cpe:2.3:o:dlink:dsr-250n_firmware:1.08b31
-
cpe:2.3:o:dlink:dsr-250n_firmware:1.08b39
-
cpe:2.3:o:dlink:dsr-500_firmware:1.02b11
-
cpe:2.3:o:dlink:dsr-500_firmware:1.02b25
-
cpe:2.3:o:dlink:dsr-500_firmware:1.03b12
-
cpe:2.3:o:dlink:dsr-500_firmware:1.03b23
-
cpe:2.3:o:dlink:dsr-500_firmware:1.03b27
-
cpe:2.3:o:dlink:dsr-500_firmware:1.03b36
-
cpe:2.3:o:dlink:dsr-500_firmware:1.03b43
-
cpe:2.3:o:dlink:dsr-500_firmware:1.04b58
-
cpe:2.3:o:dlink:dsr-500_firmware:1.06b43
-
cpe:2.3:o:dlink:dsr-500_firmware:1.06b53
-
cpe:2.3:o:dlink:dsr-500_firmware:1.08b51
-
cpe:2.3:o:dlink:dsr-500n_firmware:1.02
-
cpe:2.3:o:dlink:dsr-500n_firmware:1.02b11
-
cpe:2.3:o:dlink:dsr-500n_firmware:1.02b25
-
cpe:2.3:o:dlink:dsr-500n_firmware:1.03b12
-
cpe:2.3:o:dlink:dsr-500n_firmware:1.03b23
-
cpe:2.3:o:dlink:dsr-500n_firmware:1.03b27
-
cpe:2.3:o:dlink:dsr-500n_firmware:1.03b36
-
cpe:2.3:o:dlink:dsr-500n_firmware:1.03b43
-
cpe:2.3:o:dlink:dsr-500n_firmware:1.04b58
-
cpe:2.3:o:dlink:dsr-500n_firmware:1.06b43
-
cpe:2.3:o:dlink:dsr-500n_firmware:1.06b53
-
cpe:2.3:o:dlink:dsr-500n_firmware:1.08b51