← Vulnerability feed

Vulnerability record · CVE-2024-33113 · published 6 May 2024

CVE-2024-33113: Dlink dir-845l firmware command injection vulnerability

Dlink · Dir 845l Firmware

D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.

5.3 CVSS 3.1 Medium EPSS 3.4% · top 11.5% CWE-77 · Command injectionCWE-79 · Cross-site scripting
5.3CVSS 3.1 base score
3.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-33113 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-36756Dlink dir-845l firmware code injection vulnerabilityDIR845L A1 v1.00-v1.03 is vulnerable to command injection via /htdocs/upnpinc/gena.php.EPSS 3.2%9.8CVE-2022-38557Dlink dir-845l firmware improper authentication vulnerabilityD-Link DIR845L v1.00-v1.03 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.EPSS 0.99%9.8CVE-2022-36755Dlink dir-845l firmware improper authentication vulnerabilityD-Link DIR845L A1 contains a authentication vulnerability via an AUTHORIZED_GROUP=1 value, as demonstrated by a request for getcfg.php.EPSS 1.4%9.1CVE-2024-33110Dlink dir-845l firmware improper authentication vulnerabilityD-Link DIR-845L router v1.01KRb03 and before is vulnerable to Permission Bypass via the getcfg.php component.EPSS 0.74%9.0CVE-2024-29385Dlink dir-845l firmware command injection vulnerabilityDIR-845L router <= v1.01KRb03 has an Unauthenticated remote code execution vulnerability in the cgibin binary via soapcgi_main function.EPSS 1.6%8.8CVE-2024-29366Dlink dir-845l firmware command injection vulnerabilityA command injection vulnerability exists in the cgibin binary in DIR-845L router firmware <= v1.01KRb03.EPSS 2.4%7.5CVE-2024-33112Dlink dir-845l firmware os command injection vulnerabilityD-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func.EPSS 6.5%5.4CVE-2024-33111Dlink dir-845l firmware cross-site scripting vulnerabilityD-Link DIR-845L router <=v1.01KRb03 is vulnerable to Cross Site Scripting (XSS) via /htdocs/webinc/js/bsc_sms_inbox.php.EPSS 0.80%

Source: NIST National Vulnerability Database (record CVE-2024-33113), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.