UNLICENSED — EVALUATION ONLY

固件安全审计报告

rootfs

NYARC-ROOTFS-2026-04-23

报告日期:2026-04-23

样本: nyarc-audit-generic-4209484294/rootfs

🔒 机密 — 仅供授权人员查阅

目录

1. 执行摘要

53 / 100
2
严重
8
高危
111
中危
241
低危/信息

2. 测试范围与方法

项目详情
固件版本rootfs
厂商NETGEAR
样本文件nyarc-audit-generic-4209484294/rootfs
文件大小218.9MB
扫描时间2026-04-23
工具Nyarc Professional v1.2.0

3. 发现总览

#级别CVSS发现
1CRITICAL5.3OpenSSL libcrypto.so.1.0.0 — 已停止维护
2CRITICAL7.5OpenSSL 1.0.0 — 已停止维护
3HIGH5.3Zyxel backdoor detected (CVE-2024-40891): Shell command execution wrapper
4HIGH5.3Zyxel backdoor detected (CVE-2024-40891): Shell command execution wrapper
5HIGH5.3Zyxel backdoor detected (CVE-2024-40891): Shell command execution wrapper
6HIGH5.3Ruijie backdoor detected (CVE-2023-34644): Module call command execution interface
7HIGH5.3Ivanti backdoor detected (CVE-2025-0282): Ivanti VPN appliance (CVE-2025-0282)
8HIGH5.3Ivanti backdoor detected (CVE-2025-0282): Ivanti VPN appliance (CVE-2025-0282)
9HIGH5.3Zyxel backdoor detected (CVE-2024-40891): CLI command handler (telnet injection CVE-2024-40891)
10HIGH5.3Zyxel backdoor detected (CVE-2024-40891): CLI command handler (telnet injection CVE-2024-40891)
11MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
12MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
13MEDIUM5.3Generic potential vulnerability: Unbounded gets() input (critical overflow)
14MEDIUM5.3Generic potential vulnerability: Unbounded gets() input (critical overflow)
15MEDIUM5.3Generic potential vulnerability: Unbounded gets() input (critical overflow)
16MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
17MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
18MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
19MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
20MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
21MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
22MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
23MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
24MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
25MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
26MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
27MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
28MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
29MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
30MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
31MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
32MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
33MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
34MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
35MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
36MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
37MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
38MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
39MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
40MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
41MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
42MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
43MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
44MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
45MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
46MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
47MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
48MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
49MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
50MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
51MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
52MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
53MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
54MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
55MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
56MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
57MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
58MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
59MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
60MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
61MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
62MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
63MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
64MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
65MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
66MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
67MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
68MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
69MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
70MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
71MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
72MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
73MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
74MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
75MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
76MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
77MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
78MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
79MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
80MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
81MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
82MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
83MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
84MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
85MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
86MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
87MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
88MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
89MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
90MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
91MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
92MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
93MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
94MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
95MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
96MEDIUM5.3Generic potential vulnerability: Unbounded gets() input (critical overflow)
97MEDIUM5.3Generic potential vulnerability: Unbounded gets() input (critical overflow)
98MEDIUM5.3Generic potential vulnerability: Unbounded gets() input (critical overflow)
99MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
100MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
101MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
102MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
103MEDIUM5.3Generic potential vulnerability: Unbounded gets() input (critical overflow)
104MEDIUM5.3Generic potential vulnerability: Unbounded gets() input (critical overflow)
105MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
106MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
107MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
108MEDIUM5.3Generic potential vulnerability: Default admin credentials
109MEDIUM5.3Generic potential vulnerability: Unbounded gets() input (critical overflow)
110MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
111MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
112MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
113MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
114MEDIUM5.3Generic potential vulnerability: Unbounded gets() input (critical overflow)
115MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
116MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
117MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
118MEDIUM7.5D-Link potential vulnerability: Firmware ZIP password derived from model name
119MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
120MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)
121MEDIUM5.3D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)

4. 详细发现

1. OpenSSL libcrypto.so.1.0.0 — 已停止维护CRITICAL (CVSS 5.3)
描述
OpenSSL 1.0.x is EOL since 2020, multiple known CVEs including RCE
证据
/lib/libcrypto.so.1.0.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
ID: NYARC-001
2. OpenSSL 1.0.0 — 已停止维护CRITICAL (CVSS 7.5)
描述
OpenSSL 1.0.x is EOL since 2020, multiple known CVEs including RCE
证据
/lib/libssl.so.1.0.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ID: NYARC-002
3. Zyxel backdoor detected (CVE-2024-40891): Shell command execution wrapperHIGH (CVSS 5.3)
描述
Shell command execution wrapper
证据
/lib/libcms_cli.so
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Update firmware. Add command filtering in cmsCli_run. Block pipe, semicolon, ampersand in telnet input.
CVE
CVE-2024-40891
受影响组件
/lib/libcms_cli.so
参考链接
https://nvd.nist.gov/vuln/detail/CVE-2024-40891
ID: NYARC-003
4. Zyxel backdoor detected (CVE-2024-40891): Shell command execution wrapperHIGH (CVSS 5.3)
描述
Shell command execution wrapper
证据
/lib/libcms_core.so
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Update firmware. Add command filtering in cmsCli_run. Block pipe, semicolon, ampersand in telnet input.
CVE
CVE-2024-40891
受影响组件
/lib/libcms_core.so
参考链接
https://nvd.nist.gov/vuln/detail/CVE-2024-40891
ID: NYARC-004
5. Zyxel backdoor detected (CVE-2024-40891): Shell command execution wrapperHIGH (CVSS 5.3)
描述
Shell command execution wrapper
证据
/lib/libcms_util.so
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Update firmware. Add command filtering in cmsCli_run. Block pipe, semicolon, ampersand in telnet input.
CVE
CVE-2024-40891
受影响组件
/lib/libcms_util.so
参考链接
https://nvd.nist.gov/vuln/detail/CVE-2024-40891
ID: NYARC-005
6. Ruijie backdoor detected (CVE-2023-34644): Module call command execution interfaceHIGH (CVSS 5.3)
描述
Module call command execution interface
证据
/lib/libldb.so.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Update to firmware v219+. Add input filtering in noauth.lua merge function. Filter , $(), backtick characters.
CVE
CVE-2023-34644
受影响组件
/lib/libldb.so.1
参考链接
https://nvd.nist.gov/vuln/detail/CVE-2023-34644https://www.ruijie.com.cn/gy/xw-aqtg-gw/91389/
ID: NYARC-006
7. Ivanti backdoor detected (CVE-2025-0282): Ivanti VPN appliance (CVE-2025-0282)HIGH (CVSS 5.3)
描述
Ivanti VPN appliance (CVE-2025-0282)
证据
/www/Netgear_TNC_Italian.htm
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Patch Ivanti Connect Secure immediately.
CVE
CVE-2025-0282
受影响组件
/www/Netgear_TNC_Italian.htm
参考链接
https://nvd.nist.gov/vuln/detail/CVE-2025-0282
ID: NYARC-007
8. Ivanti backdoor detected (CVE-2025-0282): Ivanti VPN appliance (CVE-2025-0282)HIGH (CVSS 5.3)
描述
Ivanti VPN appliance (CVE-2025-0282)
证据
/www/genie_strtab_Italian
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Patch Ivanti Connect Secure immediately.
CVE
CVE-2025-0282
受影响组件
/www/genie_strtab_Italian
参考链接
https://nvd.nist.gov/vuln/detail/CVE-2025-0282
ID: NYARC-008
9. Zyxel backdoor detected (CVE-2024-40891): CLI command handler (telnet injection CVE-2024-40891)HIGH (CVSS 5.3)
描述
CLI command handler (telnet injection CVE-2024-40891)
证据
/bin/consoled_brcm
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Update firmware. Add command filtering in cmsCli_run. Block pipe, semicolon, ampersand in telnet input.
CVE
CVE-2024-40891
受影响组件
/bin/consoled_brcm
参考链接
https://nvd.nist.gov/vuln/detail/CVE-2024-40891
ID: NYARC-009
10. Zyxel backdoor detected (CVE-2024-40891): CLI command handler (telnet injection CVE-2024-40891)HIGH (CVSS 5.3)
描述
CLI command handler (telnet injection CVE-2024-40891)
证据
/lib/libcms_cli.so
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Update firmware. Add command filtering in cmsCli_run. Block pipe, semicolon, ampersand in telnet input.
CVE
CVE-2024-40891
受影响组件
/lib/libcms_cli.so
参考链接
https://nvd.nist.gov/vuln/detail/CVE-2024-40891
ID: NYARC-010
11. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/lib/libcms_dal.so
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/lib/libcms_dal.so
ID: NYARC-011
12. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/etc/bdupd_start.sh
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/etc/bdupd_start.sh
ID: NYARC-012
13. Generic potential vulnerability: Unbounded gets() input (critical overflow)MEDIUM (CVSS 5.3)
描述
Unbounded gets() input (critical overflow)
证据
/lib/libcrypto.so
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Replace gets() with fgets(). Never use gets().
受影响组件
/lib/libcrypto.so
ID: NYARC-013
14. Generic potential vulnerability: Unbounded gets() input (critical overflow)MEDIUM (CVSS 5.3)
描述
Unbounded gets() input (critical overflow)
证据
/lib/libcrypto.so.1.0.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Replace gets() with fgets(). Never use gets().
受影响组件
/lib/libcrypto.so.1.0.0
ID: NYARC-014
15. Generic potential vulnerability: Unbounded gets() input (critical overflow)MEDIUM (CVSS 5.3)
描述
Unbounded gets() input (critical overflow)
证据
/lib/libcrypto.so.1.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Replace gets() with fgets(). Never use gets().
受影响组件
/lib/libcrypto.so.1.1
ID: NYARC-015
16. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/lib/libacos_debug_log.so
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/lib/libacos_debug_log.so
ID: NYARC-016
17. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/lib/libmdm_cbk_devinfo.so
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/lib/libmdm_cbk_devinfo.so
ID: NYARC-017
18. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/lib/libmdm_cbk_diag.so
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/lib/libmdm_cbk_diag.so
ID: NYARC-018
19. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/lib/libmdm_cbk_wifi.so
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/lib/libmdm_cbk_wifi.so
ID: NYARC-019
20. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/lib/libnv2hapdcfg.so
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/lib/libnv2hapdcfg.so
ID: NYARC-020
21. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/lib/libproject_dep.so
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/lib/libproject_dep.so
ID: NYARC-021
22. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/opt/xagent/run-xagent.sh
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/opt/xagent/run-xagent.sh
ID: NYARC-022
23. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/acos_init
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/acos_init
ID: NYARC-023
24. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/acos_init
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/acos_init
ID: NYARC-024
25. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/acos_init_once
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/acos_init_once
ID: NYARC-025
26. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/acos_init_once
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/acos_init_once
ID: NYARC-026
27. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/acos_pre_init_once
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/acos_pre_init_once
ID: NYARC-027
28. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/acos_pre_init_once
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/acos_pre_init_once
ID: NYARC-028
29. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/acos_service
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/acos_service
ID: NYARC-029
30. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/acos_service
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/acos_service
ID: NYARC-030
31. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/api
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/api
ID: NYARC-031
32. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/api
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/api
ID: NYARC-032
33. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/autoconfig_wan_down
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/autoconfig_wan_down
ID: NYARC-033
34. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/autoconfig_wan_down
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/autoconfig_wan_down
ID: NYARC-034
35. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/autoconfig_wan_up
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/autoconfig_wan_up
ID: NYARC-035
36. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/autoconfig_wan_up
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/autoconfig_wan_up
ID: NYARC-036
37. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/dhcp6c_down
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/dhcp6c_down
ID: NYARC-037
38. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/dhcp6c_down
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/dhcp6c_down
ID: NYARC-038
39. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/dhcp6c_up
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/dhcp6c_up
ID: NYARC-039
40. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/dhcp6c_up
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/dhcp6c_up
ID: NYARC-040
41. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/dlna
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/dlna
ID: NYARC-041
42. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/dlna
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/dlna
ID: NYARC-042
43. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/firewall
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/firewall
ID: NYARC-043
44. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/firewall
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/firewall
ID: NYARC-044
45. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/internet
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/internet
ID: NYARC-045
46. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/internet
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/internet
ID: NYARC-046
47. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/ipv6-conntab
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/ipv6-conntab
ID: NYARC-047
48. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/ipv6-conntab
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/ipv6-conntab
ID: NYARC-048
49. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/ipv6_drop_all_pkt
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/ipv6_drop_all_pkt
ID: NYARC-049
50. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/ipv6_drop_all_pkt
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/ipv6_drop_all_pkt
ID: NYARC-050
51. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/ipv6_enable_wan_ping_to_lan
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/ipv6_enable_wan_ping_to_lan
ID: NYARC-051
52. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/ipv6_enable_wan_ping_to_lan
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/ipv6_enable_wan_ping_to_lan
ID: NYARC-052
53. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/landown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/landown
ID: NYARC-053
54. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/landown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/landown
ID: NYARC-054
55. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/lanup
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/lanup
ID: NYARC-055
56. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/lanup
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/lanup
ID: NYARC-056
57. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/ledamberup
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/ledamberup
ID: NYARC-057
58. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/ledamberup
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/ledamberup
ID: NYARC-058
59. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/ledblueup
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/ledblueup
ID: NYARC-059
60. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/ledblueup
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/ledblueup
ID: NYARC-060
61. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/leddown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/leddown
ID: NYARC-061
62. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/leddown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/leddown
ID: NYARC-062
63. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/ledgreenup
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/ledgreenup
ID: NYARC-063
64. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/ledgreenup
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/ledgreenup
ID: NYARC-064
65. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/ledredup
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/ledredup
ID: NYARC-065
66. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/ledredup
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/ledredup
ID: NYARC-066
67. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/ledup
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/ledup
ID: NYARC-067
68. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/ledup
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/ledup
ID: NYARC-068
69. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/ledwhiteup
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/ledwhiteup
ID: NYARC-069
70. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/ledwhiteup
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/ledwhiteup
ID: NYARC-070
71. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/loaddefault
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/loaddefault
ID: NYARC-071
72. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/loaddefault
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/loaddefault
ID: NYARC-072
73. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/nvconfig
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/nvconfig
ID: NYARC-073
74. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/nvconfig
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/nvconfig
ID: NYARC-074
75. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/product_alias
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/product_alias
ID: NYARC-075
76. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/product_alias
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/product_alias
ID: NYARC-076
77. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/read_bd
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/read_bd
ID: NYARC-077
78. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/read_bd
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/read_bd
ID: NYARC-078
79. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/restart_mcpd
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/restart_mcpd
ID: NYARC-079
80. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/restart_mcpd
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/restart_mcpd
ID: NYARC-080
81. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/restore_bin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/restore_bin
ID: NYARC-081
82. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/restore_bin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/restore_bin
ID: NYARC-082
83. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/routerinfo
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/routerinfo
ID: NYARC-083
84. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/routerinfo
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/routerinfo
ID: NYARC-084
85. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/system
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/system
ID: NYARC-085
86. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/system
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/system
ID: NYARC-086
87. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/te_test_d
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/te_test_d
ID: NYARC-087
88. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/uptime
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/uptime
ID: NYARC-088
89. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/uptime
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/uptime
ID: NYARC-089
90. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/version
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/version
ID: NYARC-090
91. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/version
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/version
ID: NYARC-091
92. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/wanPhydown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/wanPhydown
ID: NYARC-092
93. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/wanPhydown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/wanPhydown
ID: NYARC-093
94. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/sbin/wanPhyup
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/wanPhyup
ID: NYARC-094
95. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/sbin/wanPhyup
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/sbin/wanPhyup
ID: NYARC-095
96. Generic potential vulnerability: Unbounded gets() input (critical overflow)MEDIUM (CVSS 5.3)
描述
Unbounded gets() input (critical overflow)
证据
/share/doc/pcre/html/pcretest.html
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Replace gets() with fgets(). Never use gets().
受影响组件
/share/doc/pcre/html/pcretest.html
ID: NYARC-096
97. Generic potential vulnerability: Unbounded gets() input (critical overflow)MEDIUM (CVSS 5.3)
描述
Unbounded gets() input (critical overflow)
证据
/usr/bin/circlev2/shares/usr/lib/libcrypto.so
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Replace gets() with fgets(). Never use gets().
受影响组件
/usr/bin/circlev2/shares/usr/lib/libcrypto.so
ID: NYARC-097
98. Generic potential vulnerability: Unbounded gets() input (critical overflow)MEDIUM (CVSS 5.3)
描述
Unbounded gets() input (critical overflow)
证据
/usr/bin/circlev2/shares/usr/lib/libcrypto.so.1.0.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Replace gets() with fgets(). Never use gets().
受影响组件
/usr/bin/circlev2/shares/usr/lib/libcrypto.so.1.0.0
ID: NYARC-098
99. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/usr/lib/libacos_shared.so
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/usr/lib/libacos_shared.so
ID: NYARC-099
100. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/usr/lib/libacos_shared.so
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/usr/lib/libacos_shared.so
ID: NYARC-100
101. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/usr/lib/libdalcjson.a
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/usr/lib/libdalcjson.a
ID: NYARC-101
102. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/usr/lib/libdjson.so
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/usr/lib/libdjson.so
ID: NYARC-102
103. Generic potential vulnerability: Unbounded gets() input (critical overflow)MEDIUM (CVSS 5.3)
描述
Unbounded gets() input (critical overflow)
证据
/usr/sbin/check_fw
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Replace gets() with fgets(). Never use gets().
受影响组件
/usr/sbin/check_fw
ID: NYARC-103
104. Generic potential vulnerability: Unbounded gets() input (critical overflow)MEDIUM (CVSS 5.3)
描述
Unbounded gets() input (critical overflow)
证据
/usr/sbin/check_ra
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Replace gets() with fgets(). Never use gets().
受影响组件
/usr/sbin/check_ra
ID: NYARC-104
105. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/usr/sbin/hostapd
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/usr/sbin/hostapd
ID: NYARC-105
106. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/usr/sbin/httpd
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/usr/sbin/httpd
ID: NYARC-106
107. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/usr/sbin/httpd
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/usr/sbin/httpd
ID: NYARC-107
108. Generic potential vulnerability: Default admin credentialsMEDIUM (CVSS 5.3)
描述
Default admin credentials
证据
/usr/sbin/httpd
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/usr/sbin/httpd
ID: NYARC-108
109. Generic potential vulnerability: Unbounded gets() input (critical overflow)MEDIUM (CVSS 5.3)
描述
Unbounded gets() input (critical overflow)
证据
/usr/sbin/httpd
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Replace gets() with fgets(). Never use gets().
受影响组件
/usr/sbin/httpd
ID: NYARC-109
110. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/usr/sbin/minidlna.exe
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/usr/sbin/minidlna.exe
ID: NYARC-110
111. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/usr/sbin/pot
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/usr/sbin/pot
ID: NYARC-111
112. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/usr/sbin/upnpd
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/usr/sbin/upnpd
ID: NYARC-112
113. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/usr/sbin/upnpd
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/usr/sbin/upnpd
ID: NYARC-113
114. Generic potential vulnerability: Unbounded gets() input (critical overflow)MEDIUM (CVSS 5.3)
描述
Unbounded gets() input (critical overflow)
证据
/usr/sbin/upnpd
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Replace gets() with fgets(). Never use gets().
受影响组件
/usr/sbin/upnpd
ID: NYARC-114
115. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/usr/sbin/wl
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/usr/sbin/wl
ID: NYARC-115
116. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/usr/sbin/wpa_cli
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/usr/sbin/wpa_cli
ID: NYARC-116
117. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/usr/sbin/wpa_supplicant
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/usr/sbin/wpa_supplicant
ID: NYARC-117
118. D-Link potential vulnerability: Firmware ZIP password derived from model nameMEDIUM (CVSS 7.5)
描述
Firmware ZIP password derived from model name
证据
/bin/hspotap
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/bin/hspotap
ID: NYARC-118
119. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/bin/rastatus6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/bin/rastatus6
ID: NYARC-119
120. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/lib/libcms_core.so
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/lib/libcms_core.so
ID: NYARC-120
121. D-Link/Tenda potential vulnerability: System command execution wrapper (common injection target)MEDIUM (CVSS 5.3)
描述
System command execution wrapper (common injection target)
证据
/bin/ssk
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
修复建议
Review this component for proper input validation and access control.
受影响组件
/bin/ssk
ID: NYARC-121

📡 云控组件检测

组件类型风险外连域名
d2
/etc/init.d/d2
init.dmediumgenieremote-qa.netgear.com
hndmfg.sh
/etc/init.d/hndmfg.sh
init.dmedium192.168.1.100

5. 外连通信分析

域名分类引用
ftp.info-zip.org🟡 system
6 files
  • /usr/sbin/unzip
  • /usr/sbin/zip
  • /usr/sbin/zipcloak
  • /usr/sbin/zipinfo
  • /usr/sbin/zipnote
  • /usr/sbin/zipsplit
null.meetcircle.co🟡 system
3 files
  • /usr/bin/circlev2/shares/usr/bin/dnsmasq
  • /usr/bin/circlev2/shares/usr/bin/hosts
  • /usr/bin/circlev2/shares/usr/bin/scripts/resolv_safesearch.sh
time-d.netgear.com🟡 system
3 files
  • /usr/sbin/httpd
  • /usr/sbin/timesync
  • /usr/sbin/upnpd
strict.bing.com🟡 system
3 files
  • /usr/bin/circlev2/shares/usr/bin/dnsmasq
  • /usr/bin/circlev2/shares/usr/bin/hosts
  • /usr/bin/circlev2/shares/usr/bin/scripts/resolv_safesearch.sh
time-b.netgear.com🟡 system
3 files
  • /usr/sbin/httpd
  • /usr/sbin/timesync
  • /usr/sbin/upnpd
time-a.netgear.com🟡 system
3 files
  • /usr/sbin/httpd
  • /usr/sbin/timesync
  • /usr/sbin/upnpd
time-c.netgear.com🟡 system
3 files
  • /usr/sbin/httpd
  • /usr/sbin/timesync
  • /usr/sbin/upnpd
safe.duckduckgo.com🟡 system
3 files
  • /usr/bin/circlev2/shares/usr/bin/dnsmasq
  • /usr/bin/circlev2/shares/usr/bin/hosts
  • /usr/bin/circlev2/shares/usr/bin/scripts/resolv_safesearch.sh
device.meetcircle.co🟡 system
3 files
  • /usr/bin/circlev2/shares/usr/bin/dnsmasq
  • /usr/bin/circlev2/shares/usr/bin/hosts
  • /usr/bin/circlev2/shares/usr/bin/scripts/resolv_safesearch.sh
restrictmoderate.youtube.com🟡 system
3 files
  • /usr/bin/circlev2/shares/usr/bin/dnsmasq
  • /usr/bin/circlev2/shares/usr/bin/hosts
  • /usr/bin/circlev2/shares/usr/bin/scripts/resolv_safesearch.sh
schemas.microsoft.com🟡 system
2 files
  • /usr/sbin/upnpd
  • /www/GPL_rev1.htm
documentation.netgear.com🟡 system
2 files
  • /usr/sbin/httpd
  • /www/MNU_menu.htm
readycloud.netgear.com🟡 system
2 files
  • /usr/bin/d2d
  • /www/string_table_RAX220
updates1.netgear.com🟡 system
2 files
  • /usr/sbin/upnpd
  • /www/genie_download_href.htm
netgear-devrecog.fing.io🟡 system
  • /usr/bin/fing_dil
  • members.dyndns.org🟡 system
  • /usr/sbin/ddnsd
  • ip1.dynupdate.no🟡 system
  • /usr/sbin/ddnsd
  • ipv6.juniper.net🟡 system
  • /usr/bin/circlev2/shares/usr/bin/ipv6_only_sites.txt
  • ipv6.linuxhomepage.com🟡 system
  • /usr/bin/circlev2/shares/usr/bin/ipv6_only_sites.txt
  • getavailableseekrange.dlna.org🟡 system
  • /usr/sbin/minidlna.exe
  • ipv6.microstuff.org🟡 system
  • /usr/bin/circlev2/shares/usr/bin/ipv6_only_sites.txt
  • time-g.netgear.com🟡 system
  • /usr/sbin/timesync
  • ipv6.airbites.net🟡 system
  • /usr/bin/circlev2/shares/usr/bin/ipv6_only_sites.txt
  • api.jquery.com🟡 api
  • /www/jquery-1.8.2.js
  • ipv6.teddy.ch🟡 system
  • /usr/bin/circlev2/shares/usr/bin/ipv6_only_sites.txt
  • v6.testmyipv6.com🟡 system
  • /usr/bin/circlev2/shares/usr/bin/ipv6_only_sites.txt
  • api.jqueryui.com🟡 api
  • /www/jquery-ui-1.11.2.js
  • ipv6.worldcom.co🟡 system
  • /usr/bin/circlev2/shares/usr/bin/ipv6_only_sites.txt
  • ipv6.cloud.org🟡 system
  • /usr/bin/circlev2/shares/usr/bin/ipv6_only_sites.txt
  • testv6.cdlt.com🟡 system
  • /usr/bin/circlev2/shares/usr/bin/ipv6_only_sites.txt
  • 6. 加固建议

    建议:审查所有外连通信,更换默认凭据,升级过时的加密库。