PT-2026-35274 · D Link · Dir-822
Tian
·
Published
2026-04-26
·
Updated
2026-05-23
·
CVE-2026-7067
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-822 A 101
Description
A command injection issue exists in the udhcpd DHCP Service within the
system() function of the /udhcpcd/dhcpd.c file. A remote attacker can exploit this by manipulating the Hostname argument to execute arbitrary code. This issue occurs because the software fails to neutralize special elements within the input.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
OS Command Injection
Special Elements Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dir-822