PT-2021-6099 · D Link · D-Link Dir-878

Published

2021-12-13

·

Updated

2022-07-12

·

CVE-2021-44882

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DIR-878 versions prior to the fixed version
Description The issue is related to the implementation of the twsystem() function in the D-Link DIR-878 wireless router's firmware, which fails to neutralize special elements used in operating system commands. This allows a remote attacker to execute arbitrary commands by sending specially crafted HNAP1 POST requests to the / API endpoint, potentially via the HNAP1 protocol.
Recommendations For D-Link DIR-878 versions prior to the fixed version: update to the latest firmware version to resolve the issue. As a temporary workaround, consider restricting access to the twsystem() function until a patch is available. Avoid using the HNAP1 protocol in the affected API endpoint until the issue is resolved.

Exploit

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00770
CVE-2021-44882

Affected Products

D-Link Dir-878