PT-2021-6098 · D Link · D-Link Dir-882
Published
2021-12-13
·
Updated
2022-07-12
·
CVE-2021-44881
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DIR 882 version DIR 882 FW1.30B06 Hotfix 02
Description
The issue is related to a command injection vulnerability in the
twsystem function. This allows attackers to execute arbitrary commands via a crafted HNAP1 POST request to the / API endpoint, although the exact endpoint is not specified. The vulnerability is due to the lack of proper neutralization of special elements used in the operating system command.Recommendations
For D-Link DIR 882 version DIR 882 FW1.30B06 Hotfix 02, as a temporary workaround, consider disabling the
twsystem() function until a patch is available. Restrict access to the HNAP1 protocol to minimize the risk of exploitation. Avoid using the vulnerable function in the affected device until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dir-882