peter bassill · operator
$ cve CVE-2013-5945 JSON

CVE-2013-5945 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 9.8% (pctl 95)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 allow remote attackers to execute arbitrary SQL commands via the password to (1) the login.authenticate function in share/lua/5.1/teamf1lualib/login.lua or (2) captivePortal.lua.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS9.78% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2020-02-11
Last modified2026-06-16

Affected (16)

VendorProduct
dlinkdsr-1000
dlinkdsr-1000 firmware
dlinkdsr-1000n
dlinkdsr-1000n firmware
dlinkdsr-150
dlinkdsr-150 firmware
dlinkdsr-150n
dlinkdsr-150n firmware
dlinkdsr-250
dlinkdsr-250 firmware
dlinkdsr-250n
dlinkdsr-250n firmware
dlinkdsr-500
dlinkdsr-500 firmware
dlinkdsr-500n
dlinkdsr-500n firmware

Public exploits

SourceTitleDate
exploit-dbD-Link DSR Router Series - Remote Command Execution2013-12-06

References

→ the Explorer  ·  watch your stack  ·  NVD