Command Injection in D-Link DIR-1260 Wi-Fi Router Firmware
CVE-2022-50596
What is CVE-2022-50596?
The D-Link DIR-1260 Wi-Fi router contains a command injection flaw within its web-based management interface, affecting firmware versions up to v1.20B05. This vulnerability allows unauthenticated attackers to execute arbitrary commands with root privileges by manipulating the SetDest/Dest/Target parameters in the GetDeviceSettings form. Access to this management interface is possible over both HTTP and HTTPS on local, Wi-Fi, and optionally, Internet networks, exposing users to potential unauthorized interactions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DIR-1260 0 <= 1.20B05
References
EPSS Score
11% chance of being exploited in the next 30 days.
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved