Code Execution Vulnerability in D-Link DIR-1935 Routers
CVE-2022-43623
6.8MEDIUM
What is CVE-2022-43623?
A critical vulnerability in D-Link DIR-1935 routers enables network-adjacent attackers to execute arbitrary code on affected installations. Through manipulation of the SetWebFilterSetting requests in the web management portal, attackers can bypass existing authentication and exploit the flaw in handling user-supplied strings when parsing the WebFilterURLs element. This allows execution of system calls in the context of root, potentially compromising the integrity and confidentiality of the device.
Affected Version(s)
DIR-1935 1.03