← Vulnerability feed

Vulnerability record · CVE-2023-51123 · published 10 January 2024

CVE-2023-51123: Dlink dir-815 firmware os command injection vulnerability

Dlink · Dir 815 Firmware

An issue discovered in D-Link dir815 v.1.01SSb08.bin allows a remote attacker to execute arbitrary code via a crafted POST request to the service parameter in the soapcgi_main function of the cgibin binary component.

9.8 CVSS 3.1 Critical EPSS 24% · top 2.2% CWE-78 · OS command injection
9.8CVSS 3.1 base score
24%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue discovered in D-Link dir815 v.1.01SSb08.bin allows a remote attacker to execute arbitrary code via a crafted POST request to the service parameter in the soapcgi_main function of the cgibin binary component.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-51123 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2018-25115Dlink dir-110 firmware os command injection vulnerabilityMultiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vuln…EPSS 10%9.8CVE-2024-22651Dlink dir-815 firmware command injection vulnerabilityThere is a command injection vulnerability in the ssdpcgi_main function of cgibin binary in D-Link DIR-815 router firmware v1.04.EPSS 20%9.8CVE-2018-10106Dlink dir-815 firmware information exposure vulnerabilityD-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have permission bypass and information disclosure in /htdo…EPSS 1.9%9.8CVE-2014-8888Dlink dir-815 firmware command injection vulnerabilityThe remote administration interface in D-Link DIR-815 devices with firmware before 2.03.B02 allows remote attackers to execute arbitrary commands via…EPSS 5.3%9.8CVE-2015-0150Dlink dir-815 firmware improper access control vulnerabilityThe remote administration UI in D-Link DIR-815 devices with firmware before 2.07.B01 allows remote attackers to bypass intended access restrictions v…EPSS 2.1%9.8CVE-2015-0152Dlink dir-815 firmware information exposure vulnerabilityD-Link DIR-815 devices with firmware before 2.07.B01 allow remote attackers to obtain sensitive information by leveraging cleartext storage of the ad…EPSS 2.0%8.8CVE-2015-0151Dlink dir-815 firmware cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in D-Link DIR-815 devices with firmware before 2.07.B01 allows remote attackers to hijack the authent…EPSS 1.1%7.5CVE-2023-37758Dlink dir-815 firmware classic buffer overflow vulnerabilityD-LINK DIR-815 v1.01 was discovered to contain a buffer overflow via the component /web/captcha.cgi.EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2023-51123), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.