CVE-2022-28956: Critical severity d-link dir-816l firmware vulnerability
Published May 18, 2022
·Updated
An issue in the getcfg.php component of D-Link DIR816LFW206b01 allows attackers to access the device via a crafted payload.
Affected Software
2 affected components
Dlink Dir-816l Firmware=206b01
Dlink DIR-816L
Event History
May 18, 2022
CVE Published
via MITRE·11:50 AM
Data Sourced
via MITRE·11:50 AM
Description
Dec 6, 2023
News Published
02:45 PM
Frequently Asked Questions
1
What is CVE-2022-28956?
CVE-2022-28956 is an issue in the getcfg.php component of D-Link DIR816L_FW206b01 that allows attackers to access the device via a crafted payload.
2
What is the severity of CVE-2022-28956?
The severity of CVE-2022-28956 is critical, with a CVSS score of 9.8.
3
How can attackers exploit CVE-2022-28956?
Attackers can exploit CVE-2022-28956 by sending a crafted payload to the getcfg.php component of the D-Link DIR816L_FW206b01 device.
4
Is D-Link DIR816L_FW206b01 the only affected software?
Yes, D-Link DIR816L_FW206b01 is the only affected software by CVE-2022-28956.
5
How can I fix CVE-2022-28956?
To fix CVE-2022-28956, it is recommended to update the firmware of the D-Link DIR816L_FW206b01 device to a version that has fixed the vulnerability.