Command Injection Vulnerability in D-Link DIR-645 Router
CVE-2022-32092
9.8CRITICAL
What is CVE-2022-32092?
The D-Link DIR-645 router version 1.03 has been identified with a command injection vulnerability, which can be exploited via the QUERY_STRING parameter in the __ajax_explorer.sgi endpoint. This flaw potentially allows attackers to execute arbitrary commands on the affected device, thereby compromising its integrity and security. Users are advised to review the security bulletin by D-Link and consider applying necessary patches to mitigate this risk.