PT-2022-2561 · D Link · D-Link Dir-820L
Akast
+3
·
Published
2022-03-27
·
Updated
2025-03-13
·
CVE-2022-26258
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-820L version 1.05B03
Description
The issue is related to a remote command execution vulnerability. It can be exploited via HTTP POST to get set ccp, allowing a remote attacker to execute arbitrary commands through the
Device Name parameter in the "/lan.asp" API endpoint. The vulnerability is associated with errors in the code.Recommendations
For D-Link DIR-820L version 1.05B03, consider restricting access to the
/lan.asp API endpoint to minimize the risk of exploitation. Avoid using the Device Name parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dir-820L