← Back to CVE List
Vulnerability Intelligence Report

CVE-2013-7471

An issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 rev. B, and DIR-865 devices. There is Command Injection via shell metacharacters in the NewInternalClient, NewExternalPort, or NewInternalPort element of a SOAP POST request.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:24.04%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
dlink dir-300_firmware 2.14b01
dlink dir-300 b
dlink dir-600_firmware all
dlink dir-600 all
dlink dir-645_firmware all
dlink dir-645 all
dlink dir-845_firmware all
dlink dir-845 all
dlink dir-865_firmware 1.05b03
dlink dir-865 all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
24.044%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2019-06-11T00:00:00
Published2019-06-11T20:46:45
Last Updated2024-08-06T18:09:16

LINK COPIED TO CLIPBOARD