VYPR
Unrated severityNVD Advisory· Published Sep 22, 2023· Updated Sep 24, 2024

CVE-2023-43130

CVE-2023-43130

Description

D-Link DIR-806A1 router firmware DIR806A1_FW100CNb11 is vulnerable to command injection, allowing remote attackers to execute arbitrary commands.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

D-Link DIR-806A1 router firmware DIR806A1_FW100CNb11 is vulnerable to command injection, allowing remote attackers to execute arbitrary commands.

Vulnerability

The D-Link DIR-806 wireless router (model DIR806A1) running firmware version DIR806A1_FW100CNb11 contains a command injection vulnerability [1]. The exact input vector is not disclosed in the available references, but the vulnerability allows an attacker to inject operating system commands through a crafted request.

Exploitation

Exploitation requires network access to the router's management interface. The attacker must be able to send a specially crafted HTTP request to the vulnerable endpoint. No authentication is mentioned as required, but typical router management interfaces may require credentials. The specific steps are not detailed in the public description.

Impact

Successful exploitation results in arbitrary command execution on the device with root privileges, as the router's web interface typically runs with elevated permissions. This can lead to full compromise of the router, including data exfiltration, further network attacks, or device takeover.

Mitigation

As of the publication date (2023-09-22), no firmware update or patch has been released by D-Link to address this vulnerability. Users are advised to restrict access to the router's management interface to trusted networks and monitor for any official security advisories from D-Link [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • D-LINK/DIR-806 1200M11AC wireless routerdescription
  • Dlink/DIR-806llm-fuzzy
    Range: = DIR806A1_FW100CNb11

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.