DLink 远程代码执行漏洞(CVE-2021-27249) CVE-2021-27249 CNNVD-202104-1141

8.3 AV AC AU C I A
发布: 2021-04-14
修订: 2024-11-21

| ID | Product | Version | Vulnerability | | ------------------------------ | --------------- | ------- | ---------------------------- | | CVE-2021-27249,CVE-2021-27250 | D-Link DAP-2020 | 1.01 | Zero-Click Preauth RCE Chain | # D-LinkGATE Remote Code Execution # Description **Affected devices:** We tested our POC on the DAP-2020 (Hardwareversion: A1, Firmware-Version: 6.10) model. ![](https://images.seebug.org/1614665446156-w331s)Since the vulnerability affects a core component further models might be subject to this vulnerability. This can be checked with ZoomEye (Shodan Competitor) using the following dork: https://www.zoomeye.org/searchResult?q=%2Fwebproc ![](https://images.seebug.org/1614665449150-w331s)There currently seem to be 1.811.423 exposed, potentially vulnerable hosts. Over a million of these are exposed in Colombia. When we look at the statistics of internet users there ( _https://data.worldbank.org/indicator/IT.NET.USER.ZS?name_desc=false &locations=CO_) we notice...

0%
暂无可用Exp或PoC
当前有4条受影响产品信息