An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the dns_query_name parameter in a dns_query.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affected.
References
Link | Resource |
---|---|
https://github.com/kuc001/IoTFirmware/blob/master/D-Link/vulnerability2.md | Exploit Third Party Advisory |
https://github.com/kuc001/IoTFirmware/blob/master/Trendnet/Trendnet-TEW-632.pdf | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2020-03-07T00:30:05
Updated: 2020-03-07T00:30:04
Reserved: 2020-03-07T00:00:00
Link: CVE-2020-10215
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-03-07T01:15:15.283
Modified: 2020-03-09T17:40:11.347
Link: CVE-2020-10215
JSON object: View
Redhat Information
No data.
CWE