An issue was discovered in soap.cgi?service=WANIPConn1 on...
Critical severity
Unreviewed
Published
May 5, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Jun 11, 2019
Published to the GitHub Advisory Database
May 5, 2022
Last updated
Feb 1, 2023
An issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 rev. B, and DIR-865 devices. There is Command Injection via shell metacharacters in the NewInternalClient, NewExternalPort, or NewInternalPort element of a SOAP POST request.
References