First published: Tue May 10 2022(Updated: )
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a command injection vulnerability via the admuser and admpass parameters in /goform/setSysAdm.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-816 Firmware | =1.10cnb04 | |
Dlink DIR-816 | =a2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28915 is a command injection vulnerability found in D-Link DIR-816 A2_v1.10CNB04 firmware.
The severity of CVE-2022-28915 is rated as critical with a CVSS score of 9.8.
The affected software is D-Link DIR-816 A2 firmware version 1.10cnb04.
The vulnerability can be exploited through the admuser and admpass parameters in /goform/setSysAdm.
No specific fixes are mentioned for CVE-2022-28915. It is recommended to follow the vendor's security bulletin for updates and mitigation measures.