CVE-2022-29778: High severity d-link dir-890l firmware vulnerability
Published Jun 3, 2022
·Updated
UNSUPPORTED WHEN ASSIGNED D-Link DIR-890L 1.20b01 allows attackers to execute arbitrary code due to the hardcoded option Wake-On-Lan for the parameter 'descriptor' at SetVirtualServerSettings.php.
Affected Software
4 affected components
Dlink Dir-890l Firmware<=1.22b01
Dlink Dir-890l
All of the following
Dlink Dir-890l Firmware<=1.22b01
Dlink Dir-890l
Event History
Jun 3, 2022
CVE Published
via MITRE·08:19 PM
Data Sourced
via MITRE·08:19 PM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-29778?
CVE-2022-29778 is a vulnerability in D-Link DIR-890L 1.20b01 that allows attackers to execute arbitrary code.
2
How severe is CVE-2022-29778?
CVE-2022-29778 has a severity rating of 8.8 (high).
3
How does CVE-2022-29778 work?
CVE-2022-29778 is caused by the hardcoded option Wake-On-Lan for the parameter 'descriptor' at SetVirtualServerSettings.php.
4
What software is affected by CVE-2022-29778?
D-Link DIR-890L Firmware versions up to and including 1.22b01 are affected by CVE-2022-29778.
5
How can CVE-2022-29778 be mitigated?
There is currently no official fix or mitigation available for CVE-2022-29778. It is recommended to follow D-Link's security bulletin for updates and recommendations.