OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDlink Dir 820l
HWDlinkall versionsDlink Dir 820l Firmware
OSDlink1.05b03
CISA KEV — detailsi
- Vendori
- D-Link
- Producti
- DIR-820 Router
- Added to KEVi
- September 30, 2024
- Remediation deadline (US Federal)i
- October 21, 2024(overdue)
The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.
Related vulnerabilities
RCE w D-Link DIR-820L — command injection przez HTTP POST
RCE w routerach D-Link via DDNS — funkcja w pliku binarnym ncc2
Command Injection w narzędziu ping urządzeń D-Link i TRENDnet — RCE bez uwierzytelnienia
D-Link DIR-820L: stack overflow w funkcji sub_451208
D-Link DIR-820L — przepełnienie stosu (stack overflow) w funkcji sub_4507CC