Dlink
Dlink Dir-882 Firmware: vulnerabilidades y CVE
Dlink Dir-882 Firmware tiene 31 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 10 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE31
Últimos 12 meses5
Críticas10
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-5844 | Alta (7.3) | 6.2% | — | 9 abr 2026 | A vulnerability was found in D-Link DIR-882 1.01B02. Impacted is the function sprintf of the file prog.cgi of the component HNAP1 SetNetworkSettings Handler. The manipulation of the argument IPAddress results in os… |
| CVE-2025-60701 | Media (6.5) | 3.2% | — | 13 nov 2025 | A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_433188` function in `prog.cgi` stores user-supplied email configuration… |
| CVE-2025-60700 | Media (6.5) | 3.2% | — | 13 nov 2025 | A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `librcm.so` binaries. The `sub_4455BC` function in `prog.cgi` stores user-supplied… |
| CVE-2025-60698 | Alta (7.3) | 3.9% | — | 13 nov 2025 | A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_432F60` function in `prog.cgi` stores user-supplied… |
| CVE-2025-60697 | Alta (7.3) | 3.8% | — | 13 nov 2025 | A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_4438A4` function in `prog.cgi` stores user-supplied DDNS parameters… |
| CVE-2024-48638 | Alta (8) | 2.1% | — | 17 oct 2024 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the SubnetMask parameter in the SetGuestZoneRouterSettings function. This vulnerability allows… |
| CVE-2024-48637 | Alta (8) | 2.1% | — | 17 oct 2024 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:1/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to… |
| CVE-2024-48636 | Alta (8) | 2.1% | — | 17 oct 2024 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:0/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to… |
| CVE-2024-48635 | Alta (8) | 2.1% | — | 17 oct 2024 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:2/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to… |
| CVE-2024-48634 | Alta (8) | 18% | — | 17 oct 2024 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the key parameter in the SetWLanRadioSecurity function. This vulnerability allows attackers to… |
| CVE-2024-48633 | Alta (8) | 2.1% | — | 17 oct 2024 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the ExternalPort, InternalPort, ProtocolNumber, and LocalIPAddress parameters in the… |
| CVE-2024-48632 | Alta (8) | 2.1% | — | 17 oct 2024 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the LocalIPAddress, TCPPorts, and UDPPorts parameters in the SetPortForwardingSettings… |
| CVE-2024-48631 | Alta (8) | 2.1% | — | 17 oct 2024 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the SSID parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to… |
| CVE-2024-48630 | Alta (8) | 2.1% | — | 17 oct 2024 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the MacAddress parameter in the SetMACFilters2 function. This vulnerability allows attackers to… |
| CVE-2024-48629 | Alta (8) | 2.1% | — | 17 oct 2024 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the IPAddress parameter in the SetGuestZoneRouterSettings function. This vulnerability allows… |
| CVE-2023-24330 | Alta (8.8) | 1.3% | — | 21 feb 2024 | Command Injection vulnerability in D-Link Dir 882 with firmware version DIR882A1_FW130B06 allows attackers to run arbitrary commands via crafted POST request to /HNAP1/. |
| CVE-2024-0717 | Media (5.3) | 18% | — | 19 ene 2024 | A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825,… |
| CVE-2023-26925 | Alta (7.5) | 0.91% | — | 31 mar 2023 | An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-882 1.30. A specially crafted network request can lead to the disclosure of sensitive information. |
| CVE-2022-44807 | Crítica (9.8) | 1.3% | — | 22 nov 2022 | D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow via webGetVarString. |
| CVE-2022-44806 | Crítica (9.8) | 1.2% | — | 22 nov 2022 | D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow. |
| CVE-2022-44804 | Crítica (9.8) | 1.3% | — | 22 nov 2022 | D-Link DIR-882 1.10B02 and1.20B06 is vulnerable to Buffer Overflow via the websRedirect function. |
| CVE-2022-28901 | Crítica (9.8) | 3.5% | — | 10 may 2022 | A command injection vulnerability in the component /SetTriggerLEDBlink/Blink of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload. |
| CVE-2022-28896 | Crítica (9.8) | 3.5% | — | 10 may 2022 | A command injection vulnerability in the component /setnetworksettings/SubnetMask of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload. |
| CVE-2022-28895 | Crítica (9.8) | 3.5% | — | 10 may 2022 | A command injection vulnerability in the component /setnetworksettings/IPAddress of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload. |
| CVE-2022-28571 | Crítica (9.8) | 5.3% | — | 2 may 2022 | D-link 882 DIR882A1_FW130B06 was discovered to contain a command injection vulnerability in`/usr/bin/cli. |
| CVE-2022-1262 | Alta (7.8) | 2.2% | — | 11 abr 2022 | A command injection vulnerability in the protest binary allows an attacker with access to the remote command line interface to execute arbitrary commands as root. |
| CVE-2021-45998 | Crítica (9.8) | 3.7% | — | 4 feb 2022 | D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the LocalIPAddress parameter. This vulnerability allows attackers to execute arbitrary commands via a… |
| CVE-2021-44881 | Crítica (9.8) | 4.6% | — | 4 feb 2022 | D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted… |
| CVE-2021-44880 | Crítica (9.8) | 4.0% | — | 4 feb 2022 | D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerability in the system function. This vulnerability allows attackers to… |
| CVE-2020-8864 | Alta (8.8) | 80% | — | 23 mar 2020 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authentication is not required to exploit… |