CVE-2024-48630: Command Injection
Published Oct 17, 2024
·Updated
D-Link DIR882FW130B06 and DIR878 DIR878FW130B08 were discovered to contain a command injection vulnerability via the MacAddress parameter in the SetMACFilters2 function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
Affected Software
6 affected components
D-Link DIR-882
D-Link DIR-878
All of the following
Dlink Dir-882 Firmware=1.30b06
Dlink Dir-882
All of the following
Dlink Dir-878 Firmware=1.30b08
Dlink Dir-878
Event History
Oct 17, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-48630?
CVE-2024-48630 is classified as a medium-severity command injection vulnerability.
2
How do I fix CVE-2024-48630?
To mitigate CVE-2024-48630, update your D-Link DIR-882 or DIR-878 firmware to the latest version.
3
What devices are affected by CVE-2024-48630?
The affected devices include the D-Link DIR-882 and DIR-878 models.
4
What type of vulnerability is CVE-2024-48630?
CVE-2024-48630 is a command injection vulnerability that allows remote command execution.
5
How does CVE-2024-48630 exploit the vulnerability?
CVE-2024-48630 exploits the vulnerability through a crafted POST request targeting the MacAddress parameter in the SetMACFilters2 function.