First published: Fri Jan 27 2023(Updated: )
D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /setnetworksettings/IPAddress. This vulnerability allows attackers to escalate privileges to root via a crafted payload.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link DIR-878 firmware | =1.30b08 | |
D-Link DIR-878 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-48107 is rated as a critical vulnerability due to its potential to escalate privileges to root.
To fix CVE-2022-48107, update to the latest firmware version provided by D-Link that addresses this command injection vulnerability.
CVE-2022-48107 affects the /setnetworksettings/IPAddress component of the D-Link DIR-878 firmware.
Yes, CVE-2022-48107 can be exploited remotely by an attacker sending a crafted payload to the affected firmware.
CVE-2022-48107 specifically impacts D-Link DIR-878 firmware version 1.30b08.