First published: Fri Jun 03 2022(Updated: )
** UNSUPPORTED WHEN ASSIGNED ** D-Link DIR-890L 1.20b01 allows attackers to execute arbitrary code due to the hardcoded option Wake-On-Lan for the parameter 'descriptor' at SetVirtualServerSettings.php.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-890l Firmware | <=1.22b01 | |
Dlink Dir-890l | ||
All of | ||
Dlink Dir-890l Firmware | <=1.22b01 | |
Dlink Dir-890l |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29778 is a vulnerability in D-Link DIR-890L 1.20b01 that allows attackers to execute arbitrary code.
CVE-2022-29778 has a severity rating of 8.8 (high).
CVE-2022-29778 is caused by the hardcoded option Wake-On-Lan for the parameter 'descriptor' at SetVirtualServerSettings.php.
D-Link DIR-890L Firmware versions up to and including 1.22b01 are affected by CVE-2022-29778.
There is currently no official fix or mitigation available for CVE-2022-29778. It is recommended to follow D-Link's security bulletin for updates and recommendations.