Command Injection Vulnerability in D-Link DIR810LA1 Router
CVE-2022-34974

9.8CRITICAL

Key Information:

Vendor
D-Link
Vendor
CVE Published:
3 August 2022

Summary

An identified command injection vulnerability in the D-Link DIR810LA1_FW102B22 router allows an attacker to exploit the Ping_addr function. This weakness could enable unauthorized command execution, leading to potential unauthorized access or disruption of network services. Users are urged to review their device settings and apply necessary security updates.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.