CVE-2021-28144

prog.cgi on D-Link DIR-3060 devices before 1.11b04 HF2 allows remote authenticated users to inject arbitrary commands in an admin or root context because SetVirtualServerSettings calls CheckArpTables, which calls popen unsafely.
Configurations

Configuration 1


Information

Published : 2021-03-11 05:15

Updated : 2022-06-28 02:11


NVD link : CVE-2021-28144

Mitre link : CVE-2021-28144

Products Affected
No products.
CWE