CVE-2022-43184: OS Command Injection
D-Link DIR878 1.30B08 Hotfix04 was discovered to contain a command injection vulnerability via the component /bin/proc.cgi.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
D-Link DIR878to a version that resolves this vulnerability.Fixed in 1.30B08Patch Hotfix_04 - Compensating control
Mitigate the command injection vulnerability in /bin/proc.cgi by blocking/restricting access to the affected CGI endpoint (/bin/proc.cgi) from untrusted networks until Hotfix_04 for DIR878 1.30B08 is applied.
Event History
Frequently Asked Questions
What is CVE-2022-43184?
CVE-2022-43184 is a command injection vulnerability found in D-Link DIR878 1.30B08 Hotfix_04 firmware.
How severe is CVE-2022-43184?
CVE-2022-43184 is classified as critical with a severity value of 9.8.
What is the affected software version?
The affected software version is D-Link DIR878 1.30B08 Hotfix_04 firmware.
What are the references for CVE-2022-43184?
The references for CVE-2022-43184 are: https://github.com/HuangPayoung/CVE-request/tree/main/DLink/vuln2, https://www.dlink.com/en/security-bulletin/
How can I fix CVE-2022-43184?
To fix CVE-2022-43184, update your D-Link DIR878 firmware to a version that has addressed the vulnerability.