Arbitrary Code Execution Vulnerability in D-Link DIR-1935 Router
CVE-2022-43628
6.8MEDIUM
What is CVE-2022-43628?
A vulnerability in D-Link DIR-1935 routers allows network-adjacent attackers to bypass authentication and execute arbitrary code through the web management portal. The flaw arises from improper validation of user-supplied strings in SetIPv6FirewallSettings requests, which can lead to unauthorized system calls executed in the context of root, compromising the device's integrity. For further details, refer to the advisories from D-Link and the Zero Day Initiative.
Affected Version(s)
DIR-1935 1.03