Command Injection Vulnerability in D-Link DIR882 Network Router
CVE-2022-28896
9.8CRITICAL
What is CVE-2022-28896?
A command injection vulnerability exists in the D-Link DIR882 router, specifically within the /setnetworksettings/SubnetMask component. This flaw enables attackers to execute arbitrary commands with elevated privileges, potentially allowing unauthorized modifications to network configurations. Attackers can exploit this vulnerability by sending carefully crafted payloads, leading to serious security risks for affected systems. It emphasizes the necessity for timely updates and security patches to safeguard against exploitation.