First published: Thu Oct 13 2022(Updated: )
D-Link COVR 1200,1203 v1.08 was discovered to contain a command injection vulnerability via the tomography_ping_number parameter at function SetNetworkTomographySettings.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link Covr 1203 | =1.08 | |
Dlink Covr 1203 Firmware | ||
Dlink Covr 1202 | =1.08 | |
Dlink Covr 1202 Firmware | ||
Dlink Covr 1200 Firmware | =1.08 | |
Dlink Covr 1200 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-42156 is considered a high severity vulnerability due to its potential for command injection.
To fix CVE-2022-42156, update the D-Link COVR devices to the latest firmware version released by the manufacturer.
CVE-2022-42156 affects the D-Link COVR 1200, COVR 1202, and COVR 1203 running firmware version 1.08.
CVE-2022-42156 is a command injection vulnerability that can be exploited through the tomography_ping_number parameter.
Yes, CVE-2022-42156 can potentially be exploited remotely, allowing attackers to execute arbitrary commands on the affected devices.