CVE-2013-7471
An issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 rev. B, and DIR-865 devices. There is Command Injection via shell metacharacters in the NewInternalClient, NewExternalPort, or NewInternalPort element of a SOAP POST request.
- Affected products
- D-Link Dir-300, D-Link Dir-600, D-Link Dir-645, D-Link Dir-845L, D-Link Dir-865L
- Dlink dir-300 Firmware
- = 2.14b01
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 24.0% (98th percentile)
- Weakness
- CWE-77
- NVD status
- Modified
- Published
- 2019-06-11
CVE-2013-7471 at NVD
No indexed exploits for CVE-2013-7471 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2013-7471 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.