CVE-2022-28896: OS Command Injection
Published May 10, 2022
·Updated
A command injection vulnerability in the component /setnetworksettings/SubnetMask of D-Link DIR882 DIR882A1FW130B06 allows attackers to escalate privileges to root via a crafted payload.
Affected Software
2 affected components
Dlink Dir-882 Firmware=1.30b06
Dlink Dir-882=a1
Event History
May 10, 2022
CVE Published
via MITRE·01:17 PM
Data Sourced
via MITRE·01:17 PM
Description
Frequently Asked Questions
1
What is CVE-2022-28896?
CVE-2022-28896 is a command injection vulnerability in the component /setnetworksettings/SubnetMask of D-Link DIR882 DIR882A1_FW130B06 that allows attackers to escalate privileges to root via a crafted payload.
2
Which software versions are affected by CVE-2022-28896?
The Dlink Dir-882 Firmware version 1.30b06 is affected by CVE-2022-28896.
3
Is D-Link DIR-882A1 affected by CVE-2022-28896?
No, D-Link DIR-882A1 is not affected by CVE-2022-28896.
4
What is the severity of CVE-2022-28896?
The severity of CVE-2022-28896 is critical with a CVSS score of 9.8.
5
How can I mitigate the vulnerability CVE-2022-28896?
To mitigate the CVE-2022-28896 vulnerability, it is recommended to apply the latest firmware update provided by D-Link.