CVE-2023-24762
Description
OS Command injection vulnerability in D-Link DIR-867 DIR_867_FW1.30B07 allows attackers to execute arbitrary commands via a crafted LocalIPAddress parameter for the SetVirtualServerSettings to HNAP1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
OS command injection in D-Link DIR-867 firmware 1.30B07 allows remote attackers to execute arbitrary commands via a crafted LocalIPAddress parameter.
Vulnerability
An OS command injection vulnerability exists in D-Link DIR-867 router firmware version DIR_867_FW1.30B07. The flaw resides in the SetVirtualServerSettings action of the HNAP1 interface. By crafting a malicious LocalIPAddress parameter, an attacker can inject arbitrary operating system commands. The vulnerability is reachable when the HNAP1 service is exposed (typically on the local network).
Exploitation
An attacker with network access to the router's HNAP1 interface can send a specially crafted HTTP request to the SetVirtualServerSettings endpoint. The LocalIPAddress parameter is not properly sanitized, allowing command injection. No authentication is explicitly required by the description, but HNAP1 often requires credentials; however, the vulnerability may be exploitable without authentication if the service is misconfigured or if the attacker has valid credentials. The attacker includes shell metacharacters in the parameter value to execute arbitrary commands.
Impact
Successful exploitation allows an attacker to execute arbitrary OS commands on the router with root privileges. This can lead to full compromise of the device, including data exfiltration, installation of malware, or use of the router as a pivot point for further network attacks.
Mitigation
As of the publication date (2023-03-13), D-Link has not released a firmware update to address this vulnerability. Users should check the D-Link security bulletin page [1] for any future patches. If the device is end-of-life, no fix will be provided. As a workaround, disable remote access to the HNAP1 interface and restrict local network access to trusted devices only.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.