First published: Mon Jan 30 2017(Updated: )
An issue was discovered on the D-Link DWR-932B router. qmiweb allows command injection with ` characters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link DWR-932B Firmware | =02.02eu-revb | |
D-Link DWR-932B | ||
All of | ||
D-Link DWR-932B Firmware | =02.02eu-revb | |
D-Link DWR-932B |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10182 is classified as a high severity vulnerability due to the potential for remote command injection on the D-Link DWR-932B router.
To fix CVE-2016-10182, update the D-Link DWR-932B firmware to a version that addresses this command injection vulnerability.
CVE-2016-10182 affects the D-Link DWR-932B router with firmware version 02.02eu-revb.
Yes, CVE-2016-10182 can be exploited remotely due to the nature of the command injection vulnerability in the router's web interface.
As a workaround for CVE-2016-10182, users should restrict access to the router's web interface to trusted networks only.