CVE-2013-10069
Published: Aug 5, 2025
Modified: May 15, 2026
Description
The web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an unauthenticated OS command injection vulnerability in command.php, which improperly handles the cmd POST parameter. A remote attacker can exploit this flaw without authentication to spawn a Telnet service on a specified port, enabling persistent interactive shell access as root.
| Vendor | Product | Versions |
|---|---|---|
D-Link | DIR-600 rev B | affected 0 - <= 2.14b01 |
D-Link | DIR-300 rev B | affected 0 - <= 2.13 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now