Release date:
Updated on:
Affected Systems:
D-Link DSL2730U
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56914
CVE (CAN) ID: CVE-2012-5966
D-Link DSL2730U is a wireless router product.
The D-Link DSL2730U router has a restrictive telnet shell with limited licensing commands. After these commands are entered, they will be executed as command parameters of "sh-c. After the command is executed, the STDOUT output is returned to the telnet terminal. Authenticated attackers can link unauthorized commands through authorization commands to bypass the command whitelist.
<* Source: Nikolay dacev
Link: http://www.kb.cert.org/vuls/id/876780
Http://cwe.mitre.org/data/definitions/78.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
D-Link
------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.dlink.com/