PT-2021-6097 · D Link · D-Link Dir-882

Published

2021-12-13

·

Updated

2022-03-09

·

CVE-2021-45998

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DIR-882 versions prior to DIR 882 FW1.30B06 Hotfix 02
Description The issue is related to incorrect handling of the LocalIPAddress parameter, allowing remote attackers to execute arbitrary commands by sending specially crafted HNAP1 POST requests. This can lead to command injection, enabling attackers to perform unauthorized actions.
Recommendations For D-Link DIR-882 versions prior to DIR 882 FW1.30B06 Hotfix 02, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the HNAP1 API endpoint to minimize the risk of exploitation. Avoid using the LocalIPAddress parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00762
CVE-2021-45998

Affected Products

D-Link Dir-882