D-Link DIR-882
cpe:2.3:h:d-link:dir-882:*:*:*:*:*:*:*, +4 more
- DIR882A1_FW102B02
A command injection vulnerability has been identified in the D-Link DIR-882 Router running firmware DIR882A1_FW102B02. The issue arises in the 'prog.cgi' and 'rc' binaries, where user-supplied values for the 'SetSysLogSettings/IPAddress' are stored in NVRAM and later retrieved and executed as shell commands without proper sanitization. This vulnerability allows unauthenticated remote attackers to execute arbitrary commands on the device via crafted HTTP requests to the router's web interface.
Exploitation of this vulnerability allows for arbitrary command execution on the affected router.
To reproduce this vulnerability, send a POST request to '/cgi-bin/prog.cgi' with the 'SetSysLogSettings/IPAddress' parameter containing the injected command. The 'SetSysLogSettings/Enable' parameter should also be included to activate the syslog feature. Once the payload is injected and the syslogd command is executed, the injected command will be executed on the router.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.