D-Link DIR-822+ V1.0.2 was found to contain a command injection in SetStaticRouteSettings function. allows remote attackers to execute arbitrary commands via shell.
The vulnerability exists in the SetStaticRouteSettings function responsible for configuring static routing routes. Input data passed to this function is not properly sanitized, which allows an attacker to inject malicious shell commands. The exploit can be carried out remotely, over the network, without the need for any credentials or user interaction.
An attacker can remotely execute arbitrary system commands on the device with the privileges of the process handling the request, which in practice means the possibility of complete takeover of the router — violation of confidentiality, integrity and availability of the device and data transmitted through it.
Patches available from the manufacturer should be applied according to the references. In the absence of an available update, it is recommended to restrict access to the device's administrative interface only to trusted hosts and to disable remote management of the router from the WAN network side.
D-Link DIR-822+ in firmware version V1.0.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDlink Dir 822
HWDlinkall versionsDlink Dir 822 Firmware
OSDlink1.0.2
Related vulnerabilities
D-Link DIR-859: RCE jako root przez UPnP bez uwierzytelnienia
D-Link DIR-822+: Login bypass w interfejsie HNAP1 — puste hasło admina
Buffer overflow w D-Link DIR-822 przez protokół HNAP (SetClientInfo)
Command injection w D-Link DIR-818LW i DIR-822 przez parametr RemotePort
Command injection w D-Link DIR-822 przez parametr uplink (HNAP1)