Command Injection Vulnerability in D-Link Routers
CVE-2024-48637

Currently unrated

Key Information:

Vendor
D-Link
Vendor
CVE Published:
17 October 2024

Summary

The D-Link DIR-882 and DIR-878 routers are susceptible to a command injection vulnerability through the VLANID:1/VID parameter in the SetVLANSettings function. This security flaw enables an attacker to craft a malicious POST request that exploits the system, potentially allowing for the execution of arbitrary operating system commands. Users are advised to review their configurations and monitor for unusual activities to mitigate the risks associated with this vulnerability.

References

EPSS Score

5% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.