Command Injection Vulnerability in D-Link Routers
CVE-2024-48637

Currently unrated

Key Information:

Vendor

D-Link

Vendor
CVE Published:
17 October 2024

What is CVE-2024-48637?

The D-Link DIR-882 and DIR-878 routers are susceptible to a command injection vulnerability through the VLANID:1/VID parameter in the SetVLANSettings function. This security flaw enables an attacker to craft a malicious POST request that exploits the system, potentially allowing for the execution of arbitrary operating system commands. Users are advised to review their configurations and monitor for unusual activities to mitigate the risks associated with this vulnerability.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-48637 : Command Injection Vulnerability in D-Link Routers