CRITICAL🇵🇱 Wersja polska

CVE-2023-51984

CVSS 9.8v3.1pub. 2024-01-11upd. 2025-06-16

D-Link DIR-822+ V1.0.2 was found to contain a command injection in SetStaticRouteSettings function. allows remote attackers to execute arbitrary commands via shell.

🤖 AI Analysis
How it works

The vulnerability exists in the SetStaticRouteSettings function responsible for configuring static routing routes. Input data passed to this function is not properly sanitized, which allows an attacker to inject malicious shell commands. The exploit can be carried out remotely, over the network, without the need for any credentials or user interaction.

Impact

An attacker can remotely execute arbitrary system commands on the device with the privileges of the process handling the request, which in practice means the possibility of complete takeover of the router — violation of confidentiality, integrity and availability of the device and data transmitted through it.

Mitigation & patch

Patches available from the manufacturer should be applied according to the references. In the absence of an available update, it is recommended to restrict access to the device's administrative interface only to trusted hosts and to disable remote management of the router from the WAN network side.

Who is affected

D-Link DIR-822+ in firmware version V1.0.2

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Dlink Dir 822

    HW
    Dlink
    all versions
  • Dlink Dir 822 Firmware

    OS
    Dlink
    1.0.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2019-17621CRITICAL9.8⚠ KEVPL ✓same product

D-Link DIR-859: RCE jako root przez UPnP bez uwierzytelnienia

CVE-2023-51987CRITICAL9.8PL ✓same product

D-Link DIR-822+: Login bypass w interfejsie HNAP1 — puste hasło admina

CVE-2019-6258CRITICAL9.8PL ✓same product

Buffer overflow w D-Link DIR-822 przez protokół HNAP (SetClientInfo)

CVE-2018-19986CRITICAL9.8PL ✓same product

Command injection w D-Link DIR-818LW i DIR-822 przez parametr RemotePort

CVE-2018-19989CRITICAL9.8PL ✓same product

Command injection w D-Link DIR-822 przez parametr uplink (HNAP1)