An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the ntp_server parameter in an ntp_sync.cgi POST request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dir-825_rev.b_firmware | Dlink | 2.10 (including) | 2.10 (including) |