CVE-2022-28895: OS Command Injection
A command injection vulnerability in the component /setnetworksettings/IPAddress of D-Link DIR882 DIR882A1FW130B06 allows attackers to escalate privileges to root via a crafted payload.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-28895?
CVE-2022-28895 is a command injection vulnerability in the component /setnetworksettings/IPAddress of D-Link DIR882 DIR882A1_FW130B06 that allows attackers to escalate privileges to root via a crafted payload.
How severe is CVE-2022-28895?
CVE-2022-28895 has a severity rating of 9.8 (critical).
Which software versions are affected by CVE-2022-28895?
The D-Link DIR882 firmware version 1.30b06 is affected by CVE-2022-28895.
How can the CVE-2022-28895 vulnerability be exploited?
CVE-2022-28895 can be exploited by attackers using a crafted payload to execute commands and escalate privileges to root.
Where can I find more information about CVE-2022-28895?
You can find more information about CVE-2022-28895 in the GitHub repository at https://github.com/EPhaha/IOT_vuln/tree/main/d-link/dir-882/1 and the D-Link security bulletin at https://www.dlink.com/en/security-bulletin/