Executive brief
D-Link DWL-2600AP access points contain an authenticated OS command injection vulnerability in the Save Configuration functionality of the web interface. Attackers can execute arbitrary commands by injecting shell metacharacters into the configBackup or downloadServerip parameters of the admin.cgi script.
Affected products
- D-Link DWL-2600AP Firmware 4.2.0.15 and earlier
- D-Link DWL-2600AP
Timeline
- 2020-03-05: disclosed: NVD Published Date
- 2023-06-29: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-11-20: patched: Vendor advisory SAP10113 referenced with patch information