S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Oct 8, 2024

CVE-2023-4542 Scanner

Targets the /cgi-bin/webproc endpoint via the 'getpage' parameter, allowing unauthenticated remote attackers to execute arbitrary system commands on the device.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.3k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-4542
9.8
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient.

A vulnerability was found in D-Link DAR-8000-10 up to 20230809. It has been classified as critical. This affects an unknown part of the file /app/sys1.php. The manipulation of the argument cmd with the input id leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-238047. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
DAR-8000-10by D-Link
20230809
Updated Aug 22, 2026View on NVD →
Detail

The D-Link DAR-8000-10 is a network device commonly used in enterprise networks for managing and routing network traffic efficiently. It's developed by D-Link Corporation, a well-known company specializing in networking equipment. The DAR-8000-10 is typically implemented in environments that require robust network management and supports a wide range of network protocols to enhance connectivity. This product is crucial in setting up secure and efficient corporate networks, providing reliable and scalable networking solutions. Network administrators leverage D-Link DAR product lines like this one to facilitate various networking tasks, including data transmission and inter-networking. Its versatility and reliability make it suitable for both small businesses and larger corporations that need advanced networking capabilities.

The vulnerability CVE-2023-4542 is a command injection flaw in the D-Link DAR-8000-10 firmware. Command injection occurs when the software interprets portions of user input as commands to execute. In this case, the threat arises from unsanitized input being provided through a web interface, specifically within the CGI scripts. The lack of proper input validation allows an attacker to inject arbitrary operating system commands, which are then executed with the privileges of the web server process. This type of vulnerability is particularly dangerous because it can lead to full system compromise if exploited.

Technically, the vulnerability exists in the /cgi-bin/webproc endpoint, where the 'getpage' parameter is processed without adequate sanitization. An attacker can craft a malicious HTTP request containing shell metacharacters within this parameter, such as semicolons or pipes, to append arbitrary commands. For example, sending a request like '/cgi-bin/webproc?getpage=index&error=1&cmd=id' could execute the 'id' command on the device. The vulnerability is accessible without authentication, making it exploitable by any remote attacker who can reach the device's management interface.

If exploited, an attacker can gain complete control over the D-Link DAR-8000-10 device. This includes the ability to execute arbitrary commands, modify configurations, exfiltrate sensitive data, or use the device as a pivot point for further attacks within the network. Given the CVSS score of 9.8, the impact is critical, potentially leading to a full compromise of network integrity and confidentiality. Organizations using this device should prioritize remediation to prevent unauthorized access and maintain network security.

Solution Advice
  • Update the D-Link DAR-8000-10 firmware to the latest version provided by D-Link that patches CVE-2023-4542.
  • Restrict access to the web management interface to trusted IP addresses only using firewall rules or access control lists.
  • Disable the web management interface if not required for daily operations, or use a VPN for remote access.
  • Implement strict input validation on all CGI parameters, especially the 'getpage' parameter, to reject shell metacharacters.
  • Deploy a Web Application Firewall (WAF) with rules to detect and block command injection attempts.
  • Enable logging and monitoring for unusual HTTP requests to the /cgi-bin/webproc endpoint and investigate anomalies.
  • Segment the network to isolate the DAR-8000-10 from untrusted networks and limit lateral movement in case of compromise.
  • Regularly audit device configurations and apply security patches as soon as they are released by the vendor.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.