D-Link DNS-320 Ax Remote Command Injection Vulnerability
Release date:
Updated on:
Affected Systems:
D-Link DNS-320 Ax <= 2.04b02
Description:
--------------------------------------------------------------------------------
Bugtraq id: 68687
D-Link DNS-320 Ax is a NAS network memory.
D-Link DNS-320 Ax firmware version 2.04b02 and earlier versions have a remote command injection vulnerability in implementation, after successful exploitation can cause the root permission to execute arbitrary commands in the context of the affected device.
<* Source: Albert to Ortega
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
D-Link
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.dlink.com/
This article permanently updates the link address: