CVE-2013-7471: D-Link DIR-300 Firmware

Critical severity, CVSS 9.8. EPSS: 24% chance of exploitation in the next 30 days.

An issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 rev. B, and DIR-865 devices. There is Command Injection via shell metacharacters in the NewInternalClient, NewExternalPort, or NewInternalPort element of a SOAP POST request.

Affected products

  • D-Link DIR-300 Firmware: version 2.14b01 only
  • D-Link DIR-600 Firmware: before 2.17b01 (fixed in 2.17b01)
  • D-Link DIR-645 Firmware: before 1.04b11 (fixed in 1.04b11)
  • D-Link Dir-845 Firmware: before 1.02b03 (fixed in 1.02b03)
  • D-Link Dir-865 Firmware: version 1.05b03 only

Published 2019-06-11. Last modified 2026-06-17.