CVE-2024-48635: Command Injection
D-Link DIR882FW130B06 and DIR878 DIR878FW130B08 were discovered to contain a command injection vulnerability via the VLANID:2/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-48635?
CVE-2024-48635 is classified as a high severity command injection vulnerability.
How do I fix CVE-2024-48635?
To fix CVE-2024-48635, update the firmware of D-Link DIR-882 and DIR-878 to the latest version provided by D-Link.
What products are affected by CVE-2024-48635?
CVE-2024-48635 affects D-Link DIR-882 with firmware version 130B06 and DIR-878 with firmware version 130B08.
What types of attacks can exploit CVE-2024-48635?
Attackers can exploit CVE-2024-48635 to execute arbitrary OS commands through crafted POST requests.
Is CVE-2024-48635 remotely exploitable?
Yes, CVE-2024-48635 can be exploited remotely due to its command injection nature.