VYPR
Unrated severityNVD Advisory· Published Mar 13, 2023· Updated Mar 3, 2025

CVE-2023-24762

CVE-2023-24762

Description

OS Command injection vulnerability in D-Link DIR-867 DIR_867_FW1.30B07 allows attackers to execute arbitrary commands via a crafted LocalIPAddress parameter for the SetVirtualServerSettings to HNAP1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

OS command injection in D-Link DIR-867 firmware 1.30B07 allows remote attackers to execute arbitrary commands via a crafted LocalIPAddress parameter.

Vulnerability

An OS command injection vulnerability exists in D-Link DIR-867 router firmware version DIR_867_FW1.30B07. The flaw resides in the SetVirtualServerSettings action of the HNAP1 interface. By crafting a malicious LocalIPAddress parameter, an attacker can inject arbitrary operating system commands. The vulnerability is reachable when the HNAP1 service is exposed (typically on the local network).

Exploitation

An attacker with network access to the router's HNAP1 interface can send a specially crafted HTTP request to the SetVirtualServerSettings endpoint. The LocalIPAddress parameter is not properly sanitized, allowing command injection. No authentication is explicitly required by the description, but HNAP1 often requires credentials; however, the vulnerability may be exploitable without authentication if the service is misconfigured or if the attacker has valid credentials. The attacker includes shell metacharacters in the parameter value to execute arbitrary commands.

Impact

Successful exploitation allows an attacker to execute arbitrary OS commands on the router with root privileges. This can lead to full compromise of the device, including data exfiltration, installation of malware, or use of the router as a pivot point for further network attacks.

Mitigation

As of the publication date (2023-03-13), D-Link has not released a firmware update to address this vulnerability. Users should check the D-Link security bulletin page [1] for any future patches. If the device is end-of-life, no fix will be provided. As a workaround, disable remote access to the HNAP1 interface and restrict local network access to trusted devices only.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Dlink/DIR-867cpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: = DIR_867_FW1.30B07

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.