CVE-2017-14429
The DHCP client on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices allows unauthenticated remote code execution as root because /etc/services/INET/inet_ipv4.php mishandles shell metacharacters, affecting generated files such as WAN-1-udhcpc.sh.
- Affected products
- D-Link Dir-850L
- Dlink dir-850l Firmware
- < fw114wwb07_h2ab
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 4.9% (91th percentile)
- Weakness
- CWE-78
- NVD status
- Modified
- Published
- 2017-09-13
CVE-2017-14429 at NVD
No indexed exploits for CVE-2017-14429 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2017-14429 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.