Command Injection Vulnerability in D-Link DIR_882 and DIR_878 Products
CVE-2024-48631

Currently unrated

Key Information:

Vendor
D-Link
Vendor
CVE Published:
17 October 2024

Summary

D-Link DIR_882 and DIR_878 routers contain a command injection vulnerability through the SSID parameter in the SetWLanRadioSettings function. This security flaw enables attackers to execute arbitrary operating system commands by sending specially crafted POST requests, potentially compromising the integrity and security of the affected devices.

References

EPSS Score

5% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.