First published: Wed Oct 26 2022(Updated: )
D-Link DIR-816 A2 1.10 B05 was discovered to contain multiple command injection vulnerabilities via the admuser and admpass parameters at /goform/setSysAdm.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-816 Firmware | =1.10b05 | |
Dlink DIR-816 | =a2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for D-Link DIR-816 A2 1.10 B05 is CVE-2022-42999.
The severity of CVE-2022-42999 is high with a CVSS score of 7.5.
The affected software for CVE-2022-42999 is D-Link DIR-816 A2 1.10 B05 firmware.
The CVE references for CVE-2022-42999 are: [https://github.com/hunzi0/VulInfo/tree/main/D-Link/DIR-816/setSysAdm](https://github.com/hunzi0/VulInfo/tree/main/D-Link/DIR-816/setSysAdm) and [https://www.dlink.com/en/security-bulletin/](https://www.dlink.com/en/security-bulletin/).
The CWEs associated with CVE-2022-42999 are CWE-77 and CWE-78.