PT-2022-2561 · D Link · D-Link Dir-820L

Akast

+3

·

Published

2022-03-27

·

Updated

2025-03-13

·

CVE-2022-26258

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DIR-820L version 1.05B03
Description The issue is related to a remote command execution vulnerability. It can be exploited via HTTP POST to get set ccp, allowing a remote attacker to execute arbitrary commands through the Device Name parameter in the "/lan.asp" API endpoint. The vulnerability is associated with errors in the code.
Recommendations For D-Link DIR-820L version 1.05B03, consider restricting access to the /lan.asp API endpoint to minimize the risk of exploitation. Avoid using the Device Name parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02998
CVE-2022-26258

Affected Products

D-Link Dir-820L