VYPR
Unrated severityNVD Advisory· Published Sep 21, 2023· Updated Sep 25, 2024

CVE-2023-43128

CVE-2023-43128

Description

Command injection in D-Link DIR-806 router through HTTP_ST parameter allows remote attackers to execute arbitrary commands.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Command injection in D-Link DIR-806 router through HTTP_ST parameter allows remote attackers to execute arbitrary commands.

Vulnerability

The D-Link DIR-806 wireless router (model DIR806A1, firmware version FW100CNb11) contains a command injection vulnerability in the handling of the HTTP_ST parameter. Insufficient input validation allows injecting operating system commands via this parameter. The vulnerable firmware is FW100CNb11 for the DIR806A1 hardware revision.

Exploitation

An attacker can exploit this vulnerability by sending a crafted HTTP request to the router's web interface that includes malicious payloads within the HTTP_ST parameter. The attacker does not need prior authentication and can trigger the injection remotely over the network [1]. No user interaction beyond accessing the affected service is required.

Impact

Successful exploitation enables an unauthenticated remote attacker to execute arbitrary commands on the underlying operating system of the router with root privileges. This can lead to full compromise of the device, including data exfiltration, installation of malware, or use of the router as a pivot for further attacks on the internal network.

Mitigation

As of the publication date (2023-09-21), no official patch or firmware update has been released by D-Link to address this vulnerability [1]. Users are advised to restrict remote access to the router's management interface, place the device behind a firewall, and monitor for any security advisories from D-Link regarding this issue.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • D-LINK/DIR-806 1200M11AC wireless routerdescription
  • Dlink/DIR-806llm-fuzzy
    Range: DIR806A1_FW100CNb11

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.