Command Injection Vulnerability in D-Link Routers
CVE-2024-48630

Currently unrated

Key Information:

Vendor
D-Link
Vendor
CVE Published:
17 October 2024

Summary

D-Link DIR-882 and DIR-878 routers are impacted by a command injection issue through the MacAddress parameter in the SetMACFilters2 function. This vulnerability could allow attackers to execute arbitrary operating system commands by sending specially crafted POST requests, potentially compromising the router's integrity and security.

References

EPSS Score

5% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.