Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2013-7283 | The web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an unauthenticated OS command injection vulnerability in command.php, which improperly handles the cmd POST parameter. A remote attacker can exploit this flaw without authentication to spawn a Telnet service on a specified port, enabling persistent interactive shell access as root. |
Tue, 23 Sep 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dlink
Dlink dir-300 Dlink dir-300 Firmware Dlink dir-600 Dlink dir-600 Firmware |
|
| CPEs | cpe:2.3:h:dlink:dir-300:b:*:*:*:*:*:*:* cpe:2.3:h:dlink:dir-600:b:*:*:*:*:*:*:* cpe:2.3:o:dlink:dir-300_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:dlink:dir-600_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Dlink
Dlink dir-300 Dlink dir-300 Firmware Dlink dir-600 Dlink dir-600 Firmware |
|
| Metrics |
cvssV3_1
|
Thu, 07 Aug 2025 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
D-link
D-link dir-300 D-link dir-600 |
|
| Vendors & Products |
D-link
D-link dir-300 D-link dir-600 |
Wed, 06 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 05 Aug 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an unauthenticated OS command injection vulnerability in command.php, which improperly handles the cmd POST parameter. A remote attacker can exploit this flaw without authentication to spawn a Telnet service on a specified port, enabling persistent interactive shell access as root. | |
| Title | D-Link Devices Unauthenticated RCE | |
| Weaknesses | CWE-78 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-15T11:14:20.275Z
Reserved: 2025-08-05T15:25:58.765Z
Link: CVE-2013-10069
Updated: 2025-08-06T17:54:29.491Z
Status : Analyzed
Published: 2025-08-05T20:15:35.690
Modified: 2025-09-23T18:37:48.680
Link: CVE-2013-10069
No data.
OpenCVE Enrichment
Updated: 2025-08-06T15:12:50Z
EUVD