CVE-2022-37129
Published · Updated
25Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Attendepss 8.3%
from disclosure to weapon
Published on NVDAug 31
VulnCheck+1135d
exploitation probability
8.3%top 5% of all CVEs
observed exploitation
yesVulnCheck
D-Link DIR-816 A2_v1.10CNB04.img is vulnerable to Command Injection via /goform/SystemCommand. After the user passes in the command parameter, it will be spliced into byte_4836B0 by snprintf, and finally doSystem(&byte_4836B0); will be executed, resulting in a command injection.
Affected products
n/a · n/a