{"advisories":[{"id":"EUVD-2023-57486","source":"euvd","title":"** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 and DAR-8000 up to 20151231. It has been declared as critical. This vulnerability affects unknown code of the file /Tool/uploadfile.php. The manipulation of the argument file_upload leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240244. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.","url":"https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-57486"}],"cve":"CVE-2023-5148","epss":{"score":0.30512},"mitre":{"cpes":[],"created":"2023-09-25T01:00:08.452000+00:00","description":"** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 and DAR-8000 up to 20151231. It has been declared as critical. This vulnerability affects unknown code of the file /Tool/uploadfile.php. The manipulation of the argument file_upload leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240244. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.","metrics":{"cvssV2_0":{"score":6.5,"vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P"},"cvssV3_0":{"score":6.3,"vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},"cvssV3_1":{"score":6.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},"cvssV4_0":{}},"mitre_repo_path":"cves/2023/5xxx/CVE-2023-5148.json","references":["https://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_upload_%20uploadfile.md","https://github.com/llixixi/cve/blob/main/D-LINK-DAR-8000-10_upload_%20uploadfile.md","https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10354","https://vuldb.com/?ctiid.240244","https://vuldb.com/?id.240244"],"title":"D-Link DAR-7000/DAR-8000 uploadfile.php unrestricted upload","updated":"2024-09-24T19:16:04.891000+00:00","vendors":[],"weaknesses":["CWE-434"]},"nvd":{"cpes":["cpe:2.3:h:dlink:dar-7000:-:*:*:*:*:*:*:*","cpe:2.3:h:dlink:dar-8000:-:*:*:*:*:*:*:*","cpe:2.3:o:dlink:dar-7000_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:dlink:dar-8000_firmware:*:*:*:*:*:*:*:*"],"created":"2023-09-25T01:15:19.420000+00:00","description":"** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 and DAR-8000 up to 20151231. It has been declared as critical. This vulnerability affects unknown code of the file /Tool/uploadfile.php. The manipulation of the argument file_upload leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240244. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.","metrics":{"cvssV2_0":{"score":6.5,"vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P"},"cvssV3_0":{},"cvssV3_1":{"score":6.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},"cvssV4_0":{}},"nvd_repo_path":"2023/CVE-2023-5148.json","references":["https://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_upload_%20uploadfile.md","https://github.com/llixixi/cve/blob/main/D-LINK-DAR-8000-10_upload_%20uploadfile.md","https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10354","https://vuldb.com/?ctiid.240244","https://vuldb.com/?id.240244"],"title":null,"updated":"2026-06-17T06:47:39.257000+00:00","vendors":["dlink","dlink$PRODUCT$dar-7000","dlink$PRODUCT$dar-7000_firmware","dlink$PRODUCT$dar-8000","dlink$PRODUCT$dar-8000_firmware"],"weaknesses":["CWE-434"]},"opencve":{"changes":[{"created":"2024-09-24T20:30:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"no","Exploitation":"poc","Technical Impact":"partial"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"edf58f39-e4c3-4963-957b-79a53c90de92"}],"cpes":{"data":["cpe:2.3:h:dlink:dar-7000:-:*:*:*:*:*:*:*","cpe:2.3:h:dlink:dar-8000:-:*:*:*:*:*:*:*","cpe:2.3:o:dlink:dar-7000_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:dlink:dar-8000_firmware:*:*:*:*:*:*:*:*"],"providers":["nvd","vulnrichment"]},"created":{"data":"2023-09-25T01:00:08.452000+00:00","provider":"mitre"},"description":{"data":"** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 and DAR-8000 up to 20151231. It has been declared as critical. This vulnerability affects unknown code of the file /Tool/uploadfile.php. The manipulation of the argument file_upload leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240244. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{"score":6.5,"vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P"},"provider":"mitre"},"cvssV3_0":{"data":{"score":6.3,"vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},"provider":"mitre"},"cvssV3_1":{"data":{"score":6.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.30512},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"no","Exploitation":"poc","Technical Impact":"partial"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_upload_%20uploadfile.md","https://github.com/llixixi/cve/blob/main/D-LINK-DAR-8000-10_upload_%20uploadfile.md","https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10354","https://vuldb.com/?ctiid.240244","https://vuldb.com/?id.240244"],"providers":["mitre","nvd"]},"title":{"data":"D-Link DAR-7000/DAR-8000 uploadfile.php unrestricted upload","provider":"mitre"},"updated":{"data":"2024-11-21T08:41:09.713000+00:00","provider":"nvd"},"vendors":{"data":["dlink","dlink$PRODUCT$dar-7000","dlink$PRODUCT$dar-7000_firmware","dlink$PRODUCT$dar-8000","dlink$PRODUCT$dar-8000_firmware"],"providers":["nvd","vulnrichment"]},"weaknesses":{"data":["CWE-434"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":["cpe:2.3:o:dlink:dar-7000_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:dlink:dar-8000_firmware:*:*:*:*:*:*:*:*"],"created":"2023-09-25T01:00:08.452000+00:00","description":"** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 and DAR-8000 up to 20151231. It has been declared as critical. This vulnerability affects unknown code of the file /Tool/uploadfile.php. The manipulation of the argument file_upload leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240244. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"no","Exploitation":"poc","Technical Impact":"partial"},"version":"2.0.3"}},"references":[],"title":"D-Link DAR-7000/DAR-8000 uploadfile.php unrestricted upload","updated":"2024-09-24T19:15:59.137000+00:00","vendors":["dlink","dlink$PRODUCT$dar-7000_firmware","dlink$PRODUCT$dar-8000_firmware"],"vulnrichment_repo_path":"2023/5xxx/CVE-2023-5148.json","weaknesses":[]}}