Vulnerability Details CVE-2023-0127
A command injection vulnerability in the firmware_update command, in the device's restricted telnet interface, allows an authenticated attacker to execute arbitrary commands as root.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 60.6%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2023-0127
-
cpe:2.3:h:dlink:dwl-2600ap:-
-
cpe:2.3:o:dlink:dwl-2600ap_firmware:4.2.0.17