VYPR
Unrated severityNVD Advisory· Published Feb 4, 2022· Updated Aug 4, 2024

CVE-2021-44880

CVE-2021-44880

Description

D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerability in the system function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Command injection vulnerability in the system function of D-Link DIR-878 and DIR-882 routers allows remote attackers to execute arbitrary commands via a crafted HNAP1 POST request.

Vulnerability

A command injection vulnerability exists in the system function of D-Link DIR-878 firmware version v1.30B08_Hotfix_02 and DIR-882 firmware version v1.30B06_Hotfix_02 (both hardware revision Ax). The vulnerability is triggered by sending a specially crafted HNAP1 POST request to the device's management interface. The system function does not properly sanitize user-supplied input, allowing injection of arbitrary operating system commands. [1][2]

Exploitation

An attacker must be on the local network (LAN-side) and able to send HTTP requests to the router's web management interface. No authentication is required to exploit this vulnerability. By crafting a malicious HNAP1 POST request containing command injection payloads in the appropriate parameter, the attacker can execute arbitrary commands on the underlying operating system. [1][2]

Impact

Successful exploitation allows an unauthenticated attacker to execute arbitrary commands with root privileges on the affected router. This can lead to full compromise of the device, including data exfiltration, installation of malware, or use of the router as a pivot point for further network attacks. [1][2]

Mitigation

D-Link has released fixed firmware versions: for DIR-882, version v1.30B06_Hotfix_03 Beta is available as of February 15, 2022 [2]. For DIR-878, the advisory [1] does not explicitly list a fixed version but recommends updating to the latest firmware available on the support page. Users should apply the latest firmware updates from D-Link's support site. No workarounds are provided. [1][2]

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3
  • Dlink/DIR878cpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: =1.30B08_Hotfix_02
  • Dlink/DIR882llm-fuzzy
    Range: =1.30B06_Hotfix_02

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.