This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor D-Link First view 2018-01-12
Product Dsl-2640u Firmware Last view 2018-01-12
Version Type
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:o:d-link:dsl-2640u_firmware:im_1.00:*:*:*:*:*:*:* 1
cpe:2.3:o:d-link:dsl-2640u_firmware:me_1.00:*:*:*:*:*:*:* 1

Related : CVE

  Date Alert Description
8.8 2018-01-12 CVE-2018-5371

diag_ping.cmd on D-Link DSL-2640U devices with firmware IM_1.00 and ME_1.00, and DSL-2540U devices with firmware ME_1.00, allows authenticated remote attackers to execute arbitrary OS commands via shell metacharacters in the ipaddr field of an HTTP GET request.

CWE : Common Weakness Enumeration

%idName
100% (1) CWE-78 Improper Sanitization of Special Elements used in an OS Command ('O...