PT-2021-6097 · D Link · D-Link Dir-882
Published
2021-12-13
·
Updated
2022-03-09
·
CVE-2021-45998
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-882 versions prior to DIR 882 FW1.30B06 Hotfix 02
Description
The issue is related to incorrect handling of the
LocalIPAddress parameter, allowing remote attackers to execute arbitrary commands by sending specially crafted HNAP1 POST requests. This can lead to command injection, enabling attackers to perform unauthorized actions.Recommendations
For D-Link DIR-882 versions prior to DIR 882 FW1.30B06 Hotfix 02, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the HNAP1 API endpoint to minimize the risk of exploitation. Avoid using the
LocalIPAddress parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D-Link Dir-882