Command Injection Vulnerability in D-Link COVR 1200 Series
CVE-2022-42160
8.8HIGH
Summary
The D-Link COVR 1200 series devices, including models 1200, 1202, and 1203, are susceptible to a command injection vulnerability. This flaw arises from improper handling of the system_time_timezone parameter within the SetNTPServerSettings function. An attacker could leverage this vulnerability to inject malicious commands, potentially compromising the device's functionality and integrity. Users are advised to update their devices to the latest firmware to mitigate this risk and ensure the security of their networks.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved