D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a command injection vulnerability via the ST parameter in the lxmldbc_system() function.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/naihsin/IoT/blob/main/D-Link/DIR-600/cmd%20injection/README.md | Exploit Third Party Advisory | 
| https://github.com/naihsin/IoT/tree/main/D-Link/DIR-600/cmd%20injection | Exploit Third Party Advisory | 
| https://hackmd.io/%40naihsin/By2datZD2 | |
| https://www.dlink.com/en/security-bulletin/ | Vendor Advisory | 
| https://github.com/naihsin/IoT/blob/main/D-Link/DIR-600/cmd%20injection/README.md | Exploit Third Party Advisory | 
| https://github.com/naihsin/IoT/tree/main/D-Link/DIR-600/cmd%20injection | Exploit Third Party Advisory | 
| https://hackmd.io/%40naihsin/By2datZD2 | |
| https://www.dlink.com/en/security-bulletin/ | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
            
            
 
  | 
    
History
                    21 Nov 2024, 08:05
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://github.com/naihsin/IoT/blob/main/D-Link/DIR-600/cmd%20injection/README.md - Exploit, Third Party Advisory | |
| References | () https://github.com/naihsin/IoT/tree/main/D-Link/DIR-600/cmd%20injection - Exploit, Third Party Advisory | |
| References | () https://hackmd.io/%40naihsin/By2datZD2 - | |
| References | () https://www.dlink.com/en/security-bulletin/ - Vendor Advisory | 
07 Nov 2023, 04:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
        
        
  | 
    
        
        
  | 
16 Jun 2023, 19:35
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:h:dlink:dir-600:b5:*:*:*:*:*:*:* cpe:2.3:o:dlink:dir-600_firmware:2.18:*:*:*:*:*:*:*  | 
|
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 9.8  | 
| CWE | CWE-77 | |
| References | (MISC) https://hackmd.io/@naihsin/By2datZD2 - Exploit, Third Party Advisory | |
| References | (MISC) https://github.com/naihsin/IoT/blob/main/D-Link/DIR-600/cmd%20injection/README.md - Exploit, Third Party Advisory | |
| References | (MISC) https://www.dlink.com/en/security-bulletin/ - Vendor Advisory | |
| References | (MISC) https://github.com/naihsin/IoT/tree/main/D-Link/DIR-600/cmd%20injection - Exploit, Third Party Advisory | |
| First Time | 
        
        Dlink dir-600 Firmware
         Dlink Dlink dir-600  | 
12 Jun 2023, 20:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2023-06-12 20:15
Updated : 2024-11-21 08:05
NVD link : CVE-2023-33625
Mitre link : CVE-2023-33625
CVE.ORG link : CVE-2023-33625
JSON object : View
Products Affected
                dlink
- dir-600_firmware
 - dir-600
 
CWE
                
                    
                        
                        CWE-77
                        
            Improper Neutralization of Special Elements used in a Command ('Command Injection')
