D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerability in the system function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.
2022-02-04T02:15:07.917
2024-11-21T06:31:39.267
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | dlink | dir-878_firmware | ≤ 1.20b05 | Yes |
Operating System | dlink | dir-878_firmware | 1.30b08 | Yes |
Hardware | dlink | dir-878 | - | No |
Operating System | dlink | dir-882_firmware | ≤ 1.30b06 | Yes |
Operating System | dlink | dir-882_firmware | 1.30b06 | Yes |
Hardware | dlink | dir-882 | - | No |