← Back to browse · API

CVE-2013-10069

Severity
CRITICAL
CVSS
10.0
EPSS
0.11859
Risk score
44.15
CISA KEV
No
PoC
No
Published
2025-08-05
Modified
2026-05-15
First seen
2026-08-07
Aliases
EUVD-2013-7283, GHSA-HFJR-PXJV-X4FV
Products
D-Link:DIR-300 rev B 0 ≤2.13, D-Link:DIR-600 rev B 0 ≤2.14b01
Sources
euvd EUVD-2013-7283

Description

The web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an unauthenticated OS command injection vulnerability in command.php, which improperly handles the cmd POST parameter. A remote attacker can exploit this flaw without authentication to spawn a Telnet service on a specified port, enabling persistent interactive shell access as root.

References