Command Injection Vulnerability in D-Link Dir 882
CVE-2023-24330

Currently unrated

Key Information:

Vendor
D-Link
Vendor
CVE Published:
21 February 2024

Summary

A command injection vulnerability has been identified in D-Link Dir 882 routers, specifically in firmware version DIR882A1_FW130B06. This vulnerability allows attackers to execute arbitrary commands through specially crafted POST requests targeting the /HNAP1/ endpoint. Attackers exploiting this flaw can potentially gain unauthorized access and control over the affected device, thereby compromising the overall network security.

References

EPSS Score

8% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.