PT-2022-24318 · D Link · D-Link Dir 819

Published

2022-09-08

·

Updated

2023-08-08

·

CVE-2022-38258

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions D-Link DIR 819 version 1.06
Description A local file inclusion issue allows attackers to cause a Denial of Service or access sensitive server information via manipulation of the getpage parameter in a crafted web request. This can lead to unauthorized access to server information or disruption of service.
Recommendations For D-Link DIR 819 version 1.06, as a temporary workaround, consider restricting access to the getpage parameter in web requests until a patch is available. Avoid using the getpage parameter in crafted web requests to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-38258

Affected Products

D-Link Dir 819