Command Injection Vulnerability in D-Link Routers
CVE-2024-48637
Currently unrated
Summary
The D-Link DIR-882 and DIR-878 routers are susceptible to a command injection vulnerability through the VLANID:1/VID parameter in the SetVLANSettings function. This security flaw enables an attacker to craft a malicious POST request that exploits the system, potentially allowing for the execution of arbitrary operating system commands. Users are advised to review their configurations and monitor for unusual activities to mitigate the risks associated with this vulnerability.
References
EPSS Score
5% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved