D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.
为什么是这个 VPI(可解释·实验性)
VPI 计算依据
| 影响度 | 98.00 |
| 利用信号(KEV 收录) | ×1.50 |
| VPI | 100.00 |
VPI 公式 vpi-v1
必要措施
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.