PT-2022-2440 · D Link · D-Link Dir-825Ac G1

Published

2022-01-20

·

Updated

2022-05-06

·

CVE-2021-46441

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DIR-825AC G1 (affected versions not specified)
Description The issue is related to the incorrect handling of the cmd parameter in the cgi-bin/webupg component of the D-Link DIR-825AC G1 router's firmware. This can allow an attacker to execute arbitrary system commands using a specially crafted POST request after obtaining authorization. The lack of parameter verification in the "webupg" binary is the root cause of this problem.
Recommendations As a temporary workaround, consider disabling the cmd parameter in the affected API endpoint until a patch is available. Restrict access to the "webupg" binary to minimize the risk of exploitation. Avoid using the cmd parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02846
CVE-2021-46441

Affected Products

D-Link Dir-825Ac G1