Michael Messner, a security researcher, has identified multiple vulnerabilities in DLink DIR-600 and DIR-300 routers that allow attackers to execute arbitrary commands via shell.
According to the researcher's blog post, the vulnerabilities are caused by the absence of access restrictions and the lack of input validation in the cmd parameter.
The OS Command Injection vulnerability allows an attacker to launch telnetd and through it compromise the device.
The vulnerability is described as follows: A hacker can change the password without knowing the current password by sending malicious code to the victim's device.
The researcher found that there is no password encryption and it stores the root password in plain text in the var/passwd file.
Imagine what a hacker could do if they took control of your router by exploiting the vulnerability. They could easily redirect all your connections wherever they chose. And the choices of a malicious user would certainly not be benign.
Messner warned the company about the vulnerability, but DLink's response was that it was a browser-related issue and would not provide a fix for its routers.

