D-Link DIR-878 has inadequate filtering for special characters in the webpage input field. An unauthenticated LAN attacker can perform command injection attack to execute arbitrary system commands to control the system or disrupt service.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-31220 | D-Link DIR-878 has inadequate filtering for special characters in the webpage input field. An unauthenticated LAN attacker can perform command injection attack to execute arbitrary system commands to control the system or disrupt service. |
Fixes
Solution
Update firmware version to v1.30B08 Hotfix03
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-5972-c259e-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-17T03:07:22.208Z
Reserved: 2022-03-08T00:00:00
Link: CVE-2022-26670
No data.
Status : Modified
Published: 2022-04-07T19:15:08.957
Modified: 2024-11-21T06:54:17.920
Link: CVE-2022-26670
No data.
OpenCVE Enrichment
No data.
EUVD