← Vulnerability feed

Vulnerability record · CVE-2017-14429 · published 13 September 2017

CVE-2017-14429: Dlink dir-850l firmware os command injection vulnerability

Dlink · Dir 850l Firmware

The DHCP client on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices allows unauthenticated remote code execution as root because /etc/services/INET/inet_ipv4.php mishandles shell metacharacters, affecting generated files such as WAN-1-udhcpc.sh.

9.8 CVSS 3.1 Critical EPSS 4.9% · top 8.2% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 10.0
4.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The DHCP client on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices allows unauthenticated remote code execution as root because /etc/services/INET/inet_ipv4.php mishandles shell metacharacters, affecting generated files such as WAN-1-udhcpc.sh.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-14429 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-49004Dlink dir-850l firmware code injection vulnerabilityAn issue in D-Link DIR-850L v.B1_FW223WWb01 allows a remote attacker to execute arbitrary code via a crafted script to the en parameter.EPSS 1.9%9.8CVE-2018-20675Dlink dir-822 firmware improper authentication vulnerabilityD-Link DIR-822 C1 before v3.11B01Beta, DIR-822-US C1 before v3.11B01Beta, DIR-850L A* before v1.21B08Beta, DIR-850L B* before v2.22B03Beta, and DIR-8…EPSS 1.8%9.8CVE-2016-6563D-Link DIR routers stack buffer overflow via HNAP SOAP loginMalformed SOAP messages sent to the HNAP Login action overflow a stack buffer in several D-Link DIR router models. The vulnerable XML fields are Acti…EPSS 80%analysed9.8CVE-2018-9032Dlink dir-850l firmware improper authentication vulnerabilityAn authentication bypass vulnerability on D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router (Hardware Version : A1, B1; Firmware Version…EPSS 28%9.8CVE-2017-14417Dlink dir-850l firmware missing authentication for critical function vulnerabilityregister_send.php on D-Link DIR-850L REV. B (with firmware through FW208WWb02) devices does not require authentication, which can result in unintende…EPSS 1.3%9.8CVE-2017-14421Dlink dir-850l firmware hard-coded credentials vulnerabilityD-Link DIR-850L REV. B (with firmware through FW208WWb02) devices have a hardcoded password of wrgac25_dlink.2013gui_dir850l for the Alphanetworks ac…EPSS 2.3%8.8CVE-2018-20674Dlink dir-822 firmware vulnerabilityD-Link DIR-822 C1 before v3.11B01Beta, DIR-822-US C1 before v3.11B01Beta, DIR-850L A* before v1.21B08Beta, DIR-850L B* before v2.22B03Beta, and DIR-8…EPSS 2.5%8.8CVE-2017-3193Dlink dir-850l firmware stack-based buffer overflow vulnerabilityMultiple D-Link devices including the DIR-850L firmware versions 1.14B07 and 2.07.B05 contain a stack-based buffer overflow vulnerability in the web …EPSS 5.6%

Source: NIST National Vulnerability Database (record CVE-2017-14429), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.