← Back to browse · API

CVE-2013-10048

Severity
CRITICAL
CVSS
9.3
EPSS
0.12099
Risk score
41.43
CISA KEV
No
PoC
No
Published
2025-08-01
Modified
2026-05-15
First seen
2026-08-07
Aliases
EUVD-2013-7272, GHSA-W7GC-GXJH-PG78
Products
D-Link:DIR-300 0 ≤2.13, D-Link:DIR-600 0 ≤2.14b01
Sources
euvd EUVD-2013-7272

Description

An OS command injection vulnerability exists in various legacy D-Link routers—including DIR-300 rev B and DIR-600 (firmware ≤ 2.13 and ≤ 2.14b01, respectively)—due to improper input handling in the unauthenticated command.php endpoint. By sending specially crafted POST requests, a remote attacker can execute arbitrary shell commands with root privileges, allowing full takeover of the device. This includes launching services such as Telnet, exfiltrating credentials, modifying system configuration, and disrupting availability. The flaw stems from the lack of authentication and inadequate sanitation of the cmd parameter.

References