Command Injection Vulnerability in D-Link Routers
CVE-2024-48637
8HIGH
What is CVE-2024-48637?
The D-Link DIR-882 and DIR-878 routers are susceptible to a command injection vulnerability through the VLANID:1/VID parameter in the SetVLANSettings function. This security flaw enables an attacker to craft a malicious POST request that exploits the system, potentially allowing for the execution of arbitrary operating system commands. Users are advised to review their configurations and monitor for unusual activities to mitigate the risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved