Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2013-7471 Details

Description

An issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 rev. B, and DIR-865 devices. There is Command Injection via shell metacharacters in the NewInternalClient, NewExternalPort, or NewInternalPort element of a SOAP POST request.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://www.exploit-db.com/exploits/27044 CVEExploitThird Party AdvisoryVDB Entry
http://www.s3cur1ty.de/m1adv2013-020 CVEExploitThird Party Advisory
https://www.exploit-db.com/exploits/27044 [email protected]ExploitThird Party AdvisoryVDB Entry
http://www.s3cur1ty.de/m1adv2013-020 [email protected]ExploitThird Party Advisory

Weakness Enumeration

CWE-IDCWE NameSource
CWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')[email protected]

Affected Products

ProductVersions

Change History

5 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2013-7471
NVD Published Date:
Jun 11, 2019
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2013-7471 Details - Not Deferred