← Back to browse · API

CVE-2017-14429

Severity
CRITICAL
CVSS
9.8
EPSS
0.04923
Risk score
40.92
CISA KEV
No
PoC
No
Published
2017-09-13
Modified
2025-05-06
First seen
2026-08-07
Aliases
EUVD-2017-5932, GHSA-5GW4-H372-4W6Q
Products
n/a:n/a n/a
Sources
euvd EUVD-2017-5932

Description

The DHCP client on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices allows unauthenticated remote code execution as root because /etc/services/INET/inet_ipv4.php mishandles shell metacharacters, affecting generated files such as WAN-1-udhcpc.sh.

References