CVE detail
CVE-2013-10069 — CVE-2013-10069
Published 2025-08-05 · Modified 2026-06-16 · Vendor dlink · Product dir-600_firmware · Source nvd
CRITICAL
severity
CVSS-derived band
0.1186
EPSS probability
exploitation probability, 30d
96.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an unauthenticated OS command injection vulnerability in command.php, which improperly handles the cmd POST parameter. A remote attacker can exploit this flaw without authentication to spawn a Telnet service on a specified port, enabling persistent interactive shell access as root.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References