D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDlink Dir 820l
HWDlinkall versionsDlink Dir 820l Firmware
OSDlink1.05b03
CISA KEV — detailsi
- Vendori
- D-Link
- Producti
- DIR-820L
- Added to KEVi
- September 8, 2022
- Remediation deadline (US Federal)i
- September 29, 2022(overdue)
Required action (CISA)i
The impacted product is end-of-life and should be disconnected if still in use.
CISA descriptioni
D-Link DIR-820L contains an unspecified vulnerability in Device Name parameter in /lan.asp which allows for remote code execution.
🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
⏰CISA DEADLINE: 29 września 2022
Tags
Command Injection
References
Related vulnerabilities
CVE-2023-25280CRITICAL9.8⚠ KEVPL ✓same product
Command Injection w D-Link DIR-820L umożliwiający eskalację uprawnień do root
CVE-2021-45382CRITICAL9.8⚠ KEVPL ✓same product
RCE w routerach D-Link via DDNS — funkcja w pliku binarnym ncc2
CVE-2015-1187CRITICAL9.8⚠ KEVPL ✓same product
Command Injection w narzędziu ping urządzeń D-Link i TRENDnet — RCE bez uwierzytelnienia
CVE-2024-48150CRITICAL9.8PL ✓same product
D-Link DIR-820L: stack overflow w funkcji sub_451208
CVE-2023-44808CRITICAL9.8PL ✓same product
D-Link DIR-820L — przepełnienie stosu (stack overflow) w funkcji sub_4507CC