← Vulnerability feed

Vulnerability record · CVE-2013-7471 · published 11 June 2019

CVE-2013-7471: Dlink dir-300 firmware command injection vulnerability

Dlink · Dir 300 Firmware

An issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 rev. B, and DIR-865 devices. There is Command Injection via shell metacharacters in the NewInternalClient, NewExternalPort, or NewInternalPort element of a SOAP POST request.

9.8 CVSS 3.1 Critical EPSS 24% · top 2.2% CWE-77 · Command injection
9.8CVSS 3.1 base score, v2 7.5
24%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 rev. B, and DIR-865 devices. There is Command Injection via shell metacharacters in the NewInternalClient, NewExternalPort, or NewInternalPort element of a SOAP POST request.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.s3cur1ty.de/m1adv2013-020 ExploitThird Party Advisory
https://www.exploit-db.com/exploits/27044 ExploitThird Party AdvisoryVDB Entry
http://www.s3cur1ty.de/m1adv2013-020 ExploitThird Party Advisory
https://www.exploit-db.com/exploits/27044 ExploitThird Party AdvisoryVDB Entry

Track CVE-2013-7471 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2015-2051D-Link DIR-645 Router HNAP Command InjectionThe D-Link DIR-645 wired/wireless router (Rev. Ax, firmware 1.04b12 and earlier) fails to sanitize input to the HNAP interface, allowing command inje…KEVEPSS 97%analysed8.0CVE-2014-100005D-Link DIR-600 router CSRF enables admin account creation and remote managementThe D-Link DIR-600 (rev. Bx) with firmware before 2.17b02 is affected by multiple cross-site request forgery flaws in hedwig.cgi, pigwidgeon.cgi and …KEVEPSS 43%analysed5.7CVE-2011-4723D-Link DIR-300 router stores passwords in cleartextThe D-Link DIR-300 router stores passwords in cleartext rather than in a protected form. Anyone who can reach the stored data can read credentials di…KEVEPSS 3.1%analysed10.0CVE-2018-25115Dlink dir-110 firmware os command injection vulnerabilityMultiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vuln…EPSS 10%10.0CVE-2013-10069Dlink dir-600 firmware os command injection vulnerabilityThe web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an unauthenticated OS command in…EPSS 17%10.0CVE-2015-2052Dlink dir-645 firmware memory buffer overflow vulnerabilityStack-based buffer overflow in the DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitra…EPSS 5.2%9.8CVE-2024-41616Dlink dir-300 firmware hard-coded credentials vulnerabilityD-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service.EPSS 0.76%9.8CVE-2023-36089Dlink dir-645 firmware incorrect authorization vulnerabilityAuthentication Bypass vulnerability in D-Link DIR-645 firmware version 1.03 allows remote attackers to gain escalated privileges via function phpcgi_…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2013-7471), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.