PT-2021-6098 · D Link · D-Link Dir-882

Published

2021-12-13

·

Updated

2022-07-12

·

CVE-2021-44881

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DIR 882 version DIR 882 FW1.30B06 Hotfix 02
Description The issue is related to a command injection vulnerability in the twsystem function. This allows attackers to execute arbitrary commands via a crafted HNAP1 POST request to the / API endpoint, although the exact endpoint is not specified. The vulnerability is due to the lack of proper neutralization of special elements used in the operating system command.
Recommendations For D-Link DIR 882 version DIR 882 FW1.30B06 Hotfix 02, as a temporary workaround, consider disabling the twsystem() function until a patch is available. Restrict access to the HNAP1 protocol to minimize the risk of exploitation. Avoid using the vulnerable function in the affected device until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00766
CVE-2021-44881

Affected Products

D-Link Dir-882