CVE-2026-4499: D-Link DIR-820LW SSDP ssdpcgi_main os command injection
A vulnerability was determined in D-Link DIR-820LW 2.03. Affected is the function ssdpcgimain of the component SSDP. Executing a manipulation can lead to os command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4499?
CVE-2026-4499 is classified as a critical vulnerability due to its potential for remote exploitation via os command injection.
How do I fix CVE-2026-4499?
To mitigate CVE-2026-4499, update the D-Link DIR-820LW firmware to the latest version that addresses this vulnerability.
What component is affected by CVE-2026-4499?
CVE-2026-4499 affects the ssdpcgi_main function of the SSDP component in the D-Link DIR-820LW.
Can CVE-2026-4499 be exploited remotely?
Yes, CVE-2026-4499 can be exploited remotely, allowing attackers to execute arbitrary commands on the affected device.
Which version of D-Link DIR-820LW is impacted by CVE-2026-4499?
CVE-2026-4499 impacts D-Link DIR-820LW version 2.03.