PT-2022-3217 · D Link · D-Link Dsl-G2452Dg

Published

2022-04-11

·

Updated

2024-02-14

·

CVE-2022-28932

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions D-Link DSL-G2452DG version ME 2.00
Description The issue is related to insecure permissions in the implementation of the execute cmd.cgi script in the D-Link DSL-G2452DG router's firmware. This could allow an attacker to execute arbitrary commands due to improper permission handling.
Recommendations For D-Link DSL-G2452DG version ME 2.00, consider restricting access to the execute cmd.cgi script as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

BDU:2022-03916
CVE-2022-28932

Affected Products

D-Link Dsl-G2452Dg