Impact
The vulnerability in the Diagnostics.asp component of the D‑Link DSL‑3782 allows a malicious actor to inject arbitrary system commands through the Addr parameter. This flaw falls under CWE‑74 (Command Injection) and CWE‑77 (User-Controlled Path Traversal), giving an attacker the ability to execute arbitrary commands on the device’s operating system and compromise confidentiality, integrity, or availability of the network infrastructure.
Affected Systems
The affected product is the D‑Link DSL‑3782 router, firmware version 2016‑07‑28. No other models or firmware revisions are listed as impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity risk. The EPSS score of 1% suggests a low but non‑negligible probability of exploitation. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. An attacker can exploit the flaw remotely via the web interface, and an exploit has already been released to the public.
OpenCVE Enrichment