PT-2021-6099 · D Link · D-Link Dir-878
Published
2021-12-13
·
Updated
2022-07-12
·
CVE-2021-44882
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-878 versions prior to the fixed version
Description
The issue is related to the implementation of the
twsystem() function in the D-Link DIR-878 wireless router's firmware, which fails to neutralize special elements used in operating system commands. This allows a remote attacker to execute arbitrary commands by sending specially crafted HNAP1 POST requests to the / API endpoint, potentially via the HNAP1 protocol.Recommendations
For D-Link DIR-878 versions prior to the fixed version: update to the latest firmware version to resolve the issue. As a temporary workaround, consider restricting access to the
twsystem() function until a patch is available. Avoid using the HNAP1 protocol in the affected API endpoint until the issue is resolved.Exploit
Fix
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dir-878