Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown

CVE-2022-28901

Disclosure Date: May 10, 2022 (last updated October 07, 2023)
A command injection vulnerability in the component /SetTriggerLEDBlink/Blink of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload.
Attacker Value
Unknown

CVE-2022-28896

Disclosure Date: May 10, 2022 (last updated October 07, 2023)
A command injection vulnerability in the component /setnetworksettings/SubnetMask of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload.
Attacker Value
Unknown

CVE-2022-28895

Disclosure Date: May 10, 2022 (last updated October 07, 2023)
A command injection vulnerability in the component /setnetworksettings/IPAddress of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload.
Attacker Value
Unknown

CVE-2022-28571

Disclosure Date: May 02, 2022 (last updated October 07, 2023)
D-link 882 DIR882A1_FW130B06 was discovered to contain a command injection vulnerability in`/usr/bin/cli.
Attacker Value
Unknown

CVE-2022-1262

Disclosure Date: April 11, 2022 (last updated October 07, 2023)
A command injection vulnerability in the protest binary allows an attacker with access to the remote command line interface to execute arbitrary commands as root.
Attacker Value
Unknown

CVE-2021-45998

Disclosure Date: February 04, 2022 (last updated February 23, 2025)
D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the LocalIPAddress parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.
Attacker Value
Unknown

CVE-2021-44881

Disclosure Date: February 04, 2022 (last updated February 23, 2025)
D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.
Attacker Value
Unknown

CVE-2021-44880

Disclosure Date: February 04, 2022 (last updated February 23, 2025)
D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerability in the system function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.