CVE-2023-24762: D-Link Dir-867 Firmware

Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.

OS Command injection vulnerability in D-Link DIR-867 DIR_867_FW1.30B07 allows attackers to execute arbitrary commands via a crafted LocalIPAddress parameter for the SetVirtualServerSettings to HNAP1.

Affected products

  • D-Link Dir-867 Firmware: version 1.30b07 only

Published 2023-03-13. Last modified 2026-06-17.