First published: Tue Nov 22 2022(Updated: )
A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary operating system commands through well-designed /HNAP1 requests. Before the HNAP API function can process the request, the system function executes an untrusted command that triggers the vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-823g Firmware | =1.02b03 | |
Dlink Dir-823g |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-44808 is a command injection vulnerability found on D-Link DIR-823G devices with firmware version 1.02B03.
CVE-2022-44808 has a severity score of 9.8 (critical).
CVE-2022-44808 allows an attacker to execute arbitrary operating system commands through well-designed /HNAP1 requests on D-Link DIR-823G devices with firmware version 1.02B03.
To mitigate CVE-2022-44808, it is recommended to apply the latest firmware update provided by D-Link and keep the device up to date.
You can find more information about CVE-2022-44808 in the following references: [Link 1](https://github.com/726232111/VulIoT/tree/main/D-Link/DIR823G%20V1.0.2B05/HNAP1), [Link 2](https://github.com/RobinWang825/IoT_vuln/tree/main/D-Link/DIR-823G/2), [Link 3](https://www.dlink.com/en/security-bulletin/).