PT-2026-31585 · D Link · Dir-882

Meshaal

·

Published

2026-03-26

·

Updated

2026-04-10

·

CVE-2026-5844

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DIR-882 version 1.01B02
Description A flaw exists in the sprintf function within the prog.cgi file of the HNAP1 SetNetworkSettings Handler component. Manipulation of the IPAddress argument can lead to operating system command injection. This issue is remotely exploitable and affects a product no longer supported by the maintainer.
Recommendations Update to a newer version if available. As a temporary workaround, consider disabling the HNAP1 SetNetworkSettings Handler component until a patch is available.

Exploit

Fix

Command Injection

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2026-05156
CVE-2026-5844

Affected Products

Dir-882