← Vulnerability feed

Vulnerability record · CVE-2023-31814 · published 23 May 2023

CVE-2023-31814: Dlink dir-300 firmware vulnerability

Dlink · Dir 300 Firmware

D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.

9.8 CVSS 3.1 Critical EPSS 0.89% · top 42.4% CWE-706 · CWE-706
9.8CVSS 3.1 base score
0.89%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-31814 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

5.7CVE-2011-4723D-Link DIR-300 router stores passwords in cleartextThe D-Link DIR-300 router stores passwords in cleartext rather than in a protected form. Anyone who can reach the stored data can read credentials di…KEVEPSS 3.1%analysed10.0CVE-2013-10069Dlink dir-600 firmware os command injection vulnerabilityThe web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an unauthenticated OS command in…EPSS 17%9.8CVE-2024-41616Dlink dir-300 firmware hard-coded credentials vulnerabilityD-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service.EPSS 0.76%9.8CVE-2013-7471Dlink dir-300 firmware command injection vulnerabilityAn issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 r…EPSS 24%9.3CVE-2013-10048Dlink dir-300 firmware os command injection vulnerabilityAn OS command injection vulnerability exists in various legacy D-Link routers—including DIR-300 rev B and DIR-600 (firmware ≤ 2.13 and ≤ 2.14b01, res…EPSS 17%8.7CVE-2013-10050Dlink dir-300 firmware os command injection vulnerabilityAn OS command injection vulnerability exists in multiple D-Link routers (confirmed on DIR-300 rev A v1.05 and DIR-615 rev D v4.13) via the authentica…EPSS 14%5.3CVE-2024-0717Dlink dir-825acg1 firmware information exposure vulnerabilityA vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DI…EPSS 18%

Source: NIST National Vulnerability Database (record CVE-2023-31814), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.