CVE-2013-10048
D-Link Devices command.php Unauthenticated RCE
Vexday Risk Score
68High priority
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 9.3EPSS 12.1%KEV nãoPoC públicaNuclei —Metasploit simPatch —
Lifecycle
04 Feb 2013Metasploit module available
01 Aug 2025Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
An OS command injection vulnerability exists in various legacy D-Link routers—including DIR-300 rev B and DIR-600 (firmware ≤ 2.13 and ≤ 2.14b01, respectively)—due to improper input handling in the unauthenticated command.php endpoint. By sending specially crafted POST requests, a remote attacker can execute arbitrary shell commands with root privileges, allowing full takeover of the device. This includes launching services such as Telnet, exfiltrating credentials, modifying system configuration, and disrupting availability. The flaw stems from the lack of authentication and inadequate sanitation of the cmd parameter.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
public PoCs found — 4
cve_referenceraw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/http/dlink_command_php_exec_noauth.rbunverifiedcve_referenceweb.archive.org/web/20131022221648/http://www.s3cur1ty.de/m1adv2013-003unverifiedcve_referencewww.exploit-db.com/exploits/24453unverifiedcve_referencewww.exploit-db.com/exploits/27528unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/http/dlink_command_php_exec_noauth.rbhttps://web.archive.org/web/20131022221648/http://www.s3cur1ty.de/m1adv2013-003https://www.exploit-db.com/exploits/24453https://www.exploit-db.com/exploits/27528https://www.vulncheck.com/advisories/d-link-legacy-unauth-rce