D-Link DAP-1360U before 3.0.1 devices allow remote...
High severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Description
Published by the National Vulnerability Database
Oct 6, 2020
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Jan 29, 2023
D-Link DAP-1360U before 3.0.1 devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the IP JSON value for ping (aka res_config_action=3&res_config_id=18).
References