CVE-2022-28915: OS Command Injection
Published May 10, 2022
·Updated
D-Link DIR-816 A2v1.10CNB04 was discovered to contain a command injection vulnerability via the admuser and admpass parameters in /goform/setSysAdm.
Affected Software
2 affected components
Dlink Dir-816 Firmware=1.10cnb04
Dlink DIR-816=a2
Event History
May 10, 2022
CVE Published
via MITRE·01:16 PM
Data Sourced
via MITRE·01:16 PM
Description
Frequently Asked Questions
1
What is CVE-2022-28915?
CVE-2022-28915 is a command injection vulnerability found in D-Link DIR-816 A2_v1.10CNB04 firmware.
2
How severe is the CVE-2022-28915 vulnerability?
The severity of CVE-2022-28915 is rated as critical with a CVSS score of 9.8.
3
What is the affected software?
The affected software is D-Link DIR-816 A2 firmware version 1.10cnb04.
4
How can the CVE-2022-28915 vulnerability be exploited?
The vulnerability can be exploited through the admuser and admpass parameters in /goform/setSysAdm.
5
Are there any available fixes for CVE-2022-28915?
No specific fixes are mentioned for CVE-2022-28915. It is recommended to follow the vendor's security bulletin for updates and mitigation measures.