CVE-2022-37130: OS Command Injection
Published Aug 31, 2022
·Updated
In D-Link DIR-816 A2v1.10CNB04, DIR-878 DIR878FW1.30B08.img a command injection vulnerability occurs in /goform/Diagnosis, after the condition is met, setnum will be spliced into v10 by snprintf, and the system will be executed, resulting in a command injection vulnerability
Affected Software
2 affected components
Dlink Dir-816 Firmware=1.10cnb04
Dlink DIR-816=a2
Event History
Aug 31, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this command injection vulnerability?
The vulnerability ID is CVE-2022-37130.
2
What is the severity level of CVE-2022-37130?
The severity level of CVE-2022-37130 is critical with a score of 9.8.
3
How does the command injection vulnerability occur in D-Link DIR-816 A2_v1.10CNB04?
The command injection vulnerability occurs in /goform/Diagnosis where the parameter 'setnum' is spliced into 'v10' by snprintf, allowing system execution.
4
What is the affected software version of D-Link DIR-816 A2_v1.10CNB04?
The affected software version of D-Link DIR-816 A2_v1.10CNB04 is 1.10cnb04.
5
Is D-Link DIR-816 A2 affected by this vulnerability?
No, D-Link DIR-816 A2 is not vulnerable to this command injection vulnerability.