CVE-2022-37125: Command Injection
Published Aug 31, 2022
·Updated
D-link DIR-816 A2v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost.
Affected Software
2 affected components
Dlink Dir-816 Firmware=1.10cnb04
Dlink DIR-816=a2
Event History
Aug 31, 2022
CVE Published
via MITRE·09:42 PM
Data Sourced
via MITRE·09:42 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this D-link DIR-816 firmware?
The vulnerability ID for this D-link DIR-816 firmware is CVE-2022-37125.
2
What is the severity of CVE-2022-37125?
The severity of CVE-2022-37125 is critical with a score of 9.8.
3
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability through command injection via the /goform/NTPSyncWithHost endpoint.
4
What is the affected software version of D-link DIR-816?
The affected software version of D-link DIR-816 is A2_v1.10CNB04.img.
5
How can I fix this vulnerability?
To fix this vulnerability, update the firmware version to a secure release and apply any available patches or mitigations recommended by D-Link.