CVE-2022-26670
8.8
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
D-Link DIR-878 has inadequate filtering for special characters in the webpage input field. An unauthenticated LAN attacker can perform command injection attack to execute arbitrary system commands to control the system or disrupt service.
Affected (1)
Products: Dlink: Dir 878 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.20b05 |
| Running on/with | Platform Versions |
|---|---|
Dlink Dir 878 | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.