CVE-2013-10059
Last modified
CVE-2013-10059 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. An authenticated OS command injection vulnerability exists in various D-Link routers (tested on DIR-615H1 running firmware version 8.04) via the tools_vct.htm endpoint. The web interface fails to sanitize input passed from the ping_ipaddr parameter to the tools_vct.htm diagnostic interface, allowing attackers to inject arbitrary shell commands using backtick encapsulation. EPSS estimates a 19.11% chance of exploitation in the next 30 days.
Description
An authenticated OS command injection vulnerability exists in various D-Link routers (tested on DIR-615H1 running firmware version 8.04) via the tools_vct.htm endpoint. The web interface fails to sanitize input passed from the ping_ipaddr parameter to the tools_vct.htm diagnostic interface, allowing attackers to inject arbitrary shell commands using backtick encapsulation. With default credentials, an attacker can exploit this blind injection vector to execute arbitrary commands.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dir-615h Firmware | <= 8.04 |
References
- https://web.archive.org/web/20150921102603/http://www.s3cur1ty.de/m1adv2013-008Third Party Advisory
- https://www.vulncheck.com/advisories/d-link-legacy-os-command-injectionThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2013-10059?
How severe is CVE-2013-10059?
How do I fix CVE-2013-10059?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-10053A remote command execution vulnerability exists in ZPanel ve…8.7
- CVE-2013-10054An unauthenticated arbitrary file upload vulnerability exist…9.3
- CVE-2013-10055An unauthenticated arbitrary file upload vulnerability exist…9.3
- CVE-2013-10056Rejected reason: This CVE has the been REJECTED and will not…
- CVE-2013-10057A stack-based buffer overflow vulnerability exists in Synact…7.5
- CVE-2013-10058An authenticated OS command injection vulnerability exists i…8.6
- CVE-2013-1006WebKit, as used in Apple iTunes before 11.0.3, allows man-in…
- CVE-2013-10060An authenticated OS command injection vulnerability exists i…7.2
- CVE-2013-10061An authenticated OS command injection vulnerability exists i…7.2
- CVE-2013-10062A directory traversal vulnerability exists in Linksys router…6.9
- CVE-2013-10063A path traversal vulnerability exists in the Netgear SPH200D…6.9
- CVE-2013-10064A stack-based buffer overflow vulnerability exists in ActFax…9.3
Are you affected by CVE-2013-10059?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
