Executive brief
An OS command injection vulnerability exists in the soap.cgi component (specifically soapcgi_main in cgibin) of multiple D-Link routers. Remote attackers can execute arbitrary OS commands by submitting a crafted service parameter.
Affected products
- D-Link DIR-880L <= 1.08B04
- D-Link DIR-868L <= 1.12b04
- D-Link DIR-865L <= 1.08.B01
- D-Link DIR-860L <= 1.10b04
Timeline
- 2022-09-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-09-08: disclosed