D-Link DIR-822 A_101
cpe:2.3:h:d-link:dir-822:*:*:*:*:*:*:*, +3 more
- A_101
A command injection vulnerability has been identified in the D-Link DIR-822 router running firmware version A_101. This vulnerability resides in the udhcpd DHCP service, specifically within the file /udhcpcd/dhcpd.c. The issue arises because the DHCP server improperly sanitizes the hostname provided by clients in DHCP Option 12. This allows remote attackers to inject arbitrary commands that are executed on the router via the system function. Notably, this vulnerability affects devices that are no longer supported by D-Link.
Exploitation of this vulnerability allows for arbitrary command execution on the affected router.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.