1. Symantec/
  2. Security Response/
  3. Attack Signatures/
  4. Attack: D-Link DSL 2750B Arbitrary Command Execution

Attack: D-Link DSL 2750B Arbitrary Command Execution

Severity: High

This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.

Description

This signature detects attempts to exploit various vulnerabilities in D-Link DSL-2750B Router.

Additional Information

D-Link DSL-2750B Router is prone to an arbitrary command-execution vulnerability because it fails to sufficiently sanitize user-supplied data. Specifically, this issue occurs in the 'cli' parameter of the 'login.cgi' script.

An attacker can execute arbitrary commands and retrieve sensitive information.

Affected

  • D-Link DSL-2750B Router.

Additional References

  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube