D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were...
High severity
Unreviewed
Published
Oct 17, 2024
to the GitHub Advisory Database
•
Updated Oct 17, 2024
Description
Published by the National Vulnerability Database
Oct 17, 2024
Published to the GitHub Advisory Database
Oct 17, 2024
Last updated
Oct 17, 2024
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the ExternalPort, InternalPort, ProtocolNumber, and LocalIPAddress parameters in the SetVirtualServerSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
References