Vulnerability Details CVE-2023-24762
OS Command injection vulnerability in D-Link DIR-867 DIR_867_FW1.30B07 allows attackers to execute arbitrary commands via a crafted LocalIPAddress parameter for the SetVirtualServerSettings to HNAP1.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.017
EPSS Ranking 81.3%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2023-24762
-
cpe:2.3:h:dlink:dir-867:-
-
cpe:2.3:o:dlink:dir-867_firmware:1.30b07