PT-2026-31585 · D Link · Dir-882
Meshaal
·
Published
2026-03-26
·
Updated
2026-04-10
·
CVE-2026-5844
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-882 version 1.01B02
Description
A flaw exists in the
sprintf function within the prog.cgi file of the HNAP1 SetNetworkSettings Handler component. Manipulation of the IPAddress argument can lead to operating system command injection. This issue is remotely exploitable and affects a product no longer supported by the maintainer.Recommendations
Update to a newer version if available. As a temporary workaround, consider disabling the HNAP1 SetNetworkSettings Handler component until a patch is available.
Exploit
Fix
Command Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dir-882