PT-2022-2537 · D Link · D-Link Dir-882

CVE-2022-28571

·

Published

2022-04-01

·

Updated

2023-08-08

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-link DIR-882 version A1 FW130B06
Description A command injection issue was found in the /usr/bin/cli endpoint, related to the handling of symbolic links. This could allow a remote attacker to execute arbitrary commands due to inadequate data sanitization at the management level.
Recommendations For D-link DIR-882 version A1 FW130B06, consider disabling access to the /usr/bin/cli endpoint until a patch is available to prevent potential command injection attacks.

Exploit

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02955
CVE-2022-28571

Affected Products

D-Link Dir-882