First published: Wed Aug 31 2022(Updated: )
D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-816 Firmware | =1.10cnb04 | |
Dlink DIR-816 | =a2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this D-link DIR-816 firmware is CVE-2022-37125.
The severity of CVE-2022-37125 is critical with a score of 9.8.
An attacker can exploit this vulnerability through command injection via the /goform/NTPSyncWithHost endpoint.
The affected software version of D-link DIR-816 is A2_v1.10CNB04.img.
To fix this vulnerability, update the firmware version to a secure release and apply any available patches or mitigations recommended by D-Link.