security1 publisher
Admin credentials are the only gate on D-Link's unfixed R95 command injection
D-Link says crafted NTPServer input on the R95 reaches an OS command call in /bin/ssi, and the published vector requires administrative privileges. Proof-of-concept code is public. The investigation is open.
Publishers:supportannouncement.us.dlink.com
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+12
- Incentives68
- Confidence60