CRITICAL

CVE-2023-26613

CVSS v3

9.8

CRITICAL

EPSS Score

68.9%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

An OS command injection vulnerability in D-Link DIR-823G firmware version 1.02B05 allows unauthorized attackers to execute arbitrary operating system commands via a crafted GET request to EXCU_SHELL.

Technical details

Published
6/29/2023

Frequently asked questions

What is CVE-2023-26613?

An OS command injection vulnerability in D-Link DIR-823G firmware version 1.02B05 allows unauthorized attackers to execute arbitrary operating system commands via a crafted GET request to EXCU_SHELL.

Is CVE-2023-26613 actively exploited?

Active exploitation of CVE-2023-26613 has not been confirmed. The EPSS score is 68.9%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-26613?

CVE-2023-26613 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2023-26613 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.