Executive brief
D-Link DIR-820 routers contain an OS command injection vulnerability in the ping.ccp component. Remote, unauthenticated attackers can execute arbitrary commands with root privileges by sending a crafted payload to the ping_addr parameter.
Affected products
- D-Link DIR-820L firmware 1.05b03
- D-Link DIR-820L
Timeline
- 2023-03-15: disclosed: NVD Published Date
- 2024-09-30: kev added: Added to CISA Known Exploited Vulnerabilities Catalog