← Back to browse · API

CVE-2013-10059

Severity
HIGH
CVSS
8.6
EPSS
0.1911
Risk score
41.09
CISA KEV
No
PoC
No
Published
2025-08-01
Modified
2026-05-15
First seen
2026-08-07
Aliases
EUVD-2013-7274, GHSA-7JQP-2P5W-9CRJ
Products
D-Link:DIR-615H1 0 ≤8.04
Sources
euvd EUVD-2013-7274

Description

An authenticated OS command injection vulnerability exists in various D-Link routers (tested on DIR-615H1 running firmware version 8.04) via the tools_vct.htm endpoint. The web interface fails to sanitize input passed from the ping_ipaddr parameter to the tools_vct.htm diagnostic interface, allowing attackers to inject arbitrary shell commands using backtick encapsulation. With default credentials, an attacker can exploit this blind injection vector to execute arbitrary commands.

References