#VU49091 Hidden functionality in DSL-2888A - CVE-2020-24581
Published: December 18, 2020
DSL-2888A
D-Link
Description
The vulnerability allows a remote user to escalate privileges on the device.
The vulnerability exists due to presence of hidden functionality in firmware. A remote authenticated user can execute arbitrary OS commands via "cmd" parameter to "/cgi-bin/execute_cmd.cgi" script.
Example:
http://DeviceIP/cgi-bin/execute_cmd.cgi?timestamp=1589333279490&cmd=ls