In DLink DAP-1360 F1 firmware version <=v6.10 in the webupg binary, an attacker can use the file parameter to execute arbitrary system commands when the parameter is name=deleteFile after being authorized.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dap-1360f1_firmware | Dlink | * | 6.10 (including) |