CVE-2022-28901: OS Command Injection
A command injection vulnerability in the component /SetTriggerLEDBlink/Blink of D-Link DIR882 DIR882A1FW130B06 allows attackers to escalate privileges to root via a crafted payload.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this command injection vulnerability?
The vulnerability ID of this command injection vulnerability is CVE-2022-28901.
What is the severity of CVE-2022-28901?
The severity of CVE-2022-28901 is critical with a CVSS score of 9.8.
What is the affected software for CVE-2022-28901?
The affected software for CVE-2022-28901 is D-Link DIR882 with firmware version 1.30b06.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by sending a crafted payload to the /SetTriggerLEDBlink/Blink component of the D-Link DIR882 router.
Are there any references available for CVE-2022-28901?
Yes, you can find references for CVE-2022-28901 at the following links: [link1](https://github.com/EPhaha/IOT_vuln/tree/main/d-link/dir-882/3), [link2](https://www.dlink.com/en/security-bulletin/).