PT-2022-3370 · D Link · D-Link Dir-645
Feixincheng
+2
·
Published
2022-05-31
·
Updated
2023-08-08
·
CVE-2022-32092
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-645 version 1.03
Description
The issue is related to a command injection vulnerability in the ajax explorer.sgi file of the D-Link DIR-645 router's firmware. This vulnerability arises from the failure to neutralize special elements used in the operating system command when processing the
QUERY STRING parameter. Exploitation of this issue may allow an attacker to execute arbitrary commands.Recommendations
For D-Link DIR-645 version 1.03, consider restricting access to the
ajax explorer.sgi file until a patch is available. As a temporary workaround, avoid using the QUERY STRING parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dir-645