CVE-2013-10048: critical vulnerability in D-Link DIR-300
D-Link Devices command.php Unauthenticated RCE
Published · Updated
68Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 9.3epss 17%
from disclosure to weapon0 days
Published on NVDAug 1
metasploitFeb 4
exploitation probability
17%top 3% of all CVEs
observed exploitation
nono source reports it
4 public exploit(s)
An OS command injection vulnerability exists in various legacy D-Link routers—including DIR-300 rev B and DIR-600 (firmware ≤ 2.13 and ≤ 2.14b01, respectively)—due to improper input handling in the unauthenticated command.php endpoint. By sending specially crafted POST requests, a remote attacker can execute arbitrary shell commands with root privileges, allowing full takeover of the device. This includes launching services such as Telnet, exfiltrating credentials, modifying system configuration, and disrupting availability. The flaw stems from the lack of authentication and inadequate sanitation of the cmd parameter.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
public PoCs found — 4
cve_referenceraw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/http/dlink_command_php_exec_noauth.rbunverifiedcve_referenceweb.archive.org/web/20131022221648/http://www.s3cur1ty.de/m1adv2013-003unverifiedcve_referencewww.exploit-db.com/exploits/24453unverifiedcve_referencewww.exploit-db.com/exploits/27528unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — D-Link DIR-300
In the same product, most dangerous first.
CVE-2024-0717MEDIUMD-Link Good Line Router v2 HTTP GET Request devinfo information disclosureEPSS 18.2%CVE-2018-25115CRITICALD-Link DIR-110/412/600/615/645/815 RCE via service.cgiEPSS 10.1%CVE-2026-2163MEDIUMD-Link DIR-600 ssdp.cgi command injectionEPSS 6.6%CVE-2024-7357MEDIUMD-Link DIR-600 soap.cgi soapcgi_main os command injectionEPSS 5.7%CVE-2025-15194CRITICALD-Link DIR-600 HTTP Header hedwig.cgi stack-based overflowEPSS 1.2%CVE-2026-0625CRITICALD-Link DSL/DIR/DNS Authentication Bypass via DNS Configuration EndpointEPSS 1.0%
References
https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/http/dlink_command_php_exec_noauth.rbhttps://web.archive.org/web/20131022221648/http://www.s3cur1ty.de/m1adv2013-003https://www.exploit-db.com/exploits/24453https://www.exploit-db.com/exploits/27528https://www.vulncheck.com/advisories/d-link-legacy-unauth-rce