CVE-2022-28958: D-Link DIR-816L Remote Code Execution Vulnerability
DISPUTED D-Link DIR816LFW206b01 was discovered to contain a remote code execution (RCE) vulnerability via the value parameter at shareport.php. NOTE: this has been disputed by a third party.
Other sources
D-Link DIR-816L contains an unspecified vulnerability in the shareport.php value parameter which allows for remote code execution.
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-28958?
CVE-2022-28958 is a remote code execution (RCE) vulnerability found in the D-Link DIR-816L router.
How severe is CVE-2022-28958?
CVE-2022-28958 has a severity rating of 9.8 (critical).
Which software or products are affected by CVE-2022-28958?
The D-Link DIR-816L router firmware version 206b01 is affected by CVE-2022-28958.
How can I fix CVE-2022-28958?
To fix CVE-2022-28958, update the D-Link DIR-816L router firmware to a version that is not vulnerable.
Where can I find more information about CVE-2022-28958?
You can find more information about CVE-2022-28958 at the following references: [Link 1](https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10300), [Link 2](https://github.com/shijin0925/IOT/blob/master/DIR816/3.md), [Link 3](https://vulncheck.com/blog/moobot-uses-fake-vulnerability)