CVE-2022-44832: Command Injection
Published Dec 14, 2022
·Updated
D-Link DIR-3040 device with firmware 120B03 was discovered to contain a command injection vulnerability via the SetTriggerLEDBlink function.
Affected Software
4 affected components
Dlink Dir-3040 Firmware=120b03
Dlink DIR-3040
All of the following
Dlink Dir-3040 Firmware=120b03
Dlink DIR-3040
Event History
Dec 14, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-44832?
CVE-2022-44832 is a command injection vulnerability that affects the D-Link DIR-3040 device with firmware version 120B03.
2
How severe is CVE-2022-44832?
CVE-2022-44832 has a severity rating of 9.8 (critical).
3
How does CVE-2022-44832 affect the D-Link DIR-3040 device?
CVE-2022-44832 allows attackers to execute arbitrary commands on the D-Link DIR-3040 device via the SetTriggerLEDBlink function.
4
Is the D-Link DIR-3040 device with firmware version 120B03 vulnerable to CVE-2022-44832?
Yes, the D-Link DIR-3040 device with firmware version 120B03 is vulnerable to CVE-2022-44832.
5
How can I fix CVE-2022-44832?
To fix CVE-2022-44832, it is recommended to update the firmware of the D-Link DIR-3040 device to a version that addresses the vulnerability.