Vulnerability Details CVE-2023-25280
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.931
EPSS Ranking 99.8%
CVSS Severity
CVSS v3 Score 9.8
Proposed Action
D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.
Ransomware Campaign
Unknown
Products affected by CVE-2023-25280
-
cpe:2.3:h:dlink:dir820la1:-
-
cpe:2.3:o:dlink:dir820la1_firmware:105b03