Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Tyeyeah

#29166of 53,622
8.8Total CVSS
Vulnerabilities · 1
PT-2022-19827
8.8
2022-06-03
D Link · D-Link Dir-890L · CVE-2022-29778
**Name of the Vulnerable Software and Affected Versions** D-Link DIR-890L version 1.20b01 **Description** The issue allows attackers to execute arbitrary code due to the hardcoded option Wake-On-Lan for the parameter `descriptor` at the API endpoint "SetVirtualServerSettings.php". **Recommendations** For D-Link DIR-890L version 1.20b01, consider disabling the Wake-On-Lan option as a temporary workaround until a patch is available. Restrict access to the SetVirtualServerSettings.php endpoint to minimize the risk of exploitation. Avoid using the parameter `descriptor` in the affected API endpoint until the issue is resolved.