PT-2024-3191 · D Link · D-Link Dir-822

Published

2024-04-23

·

Updated

2024-07-03

·

CVE-2024-33342

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DIR-822+ version 1.0.5
Description The issue is related to a command injection in the SetPlcNetworkpwd function of the prog.cgi script, which allows remote attackers to execute arbitrary commands via shell. This is due to the lack of proper sanitization of special elements used in the operating system command when processing the local plc parameter. Exploitation of this issue can enable a remote attacker to execute arbitrary commands.
Recommendations For D-Link DIR-822+ version 1.0.5, as a temporary workaround, consider disabling the SetPlcNetworkpwd function until a patch is available. Restrict access to the prog.cgi script to minimize the risk of exploitation. Avoid using the local plc parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-03411
CVE-2024-33342

Affected Products

D-Link Dir-822