Critical severity9.8NVD Advisory· Published Feb 4, 2022· Updated Jun 17, 2026
CVE-2021-44880
CVE-2021-44880
Description
D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerability in the system function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:o:dlink:dir-878_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:dlink:dir-878_firmware:*:*:*:*:*:*:*:*range: <=1.20b05
- cpe:2.3:o:dlink:dir-878_firmware:1.30b08:hotfix_02_beta:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-882_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:dlink:dir-882_firmware:*:*:*:*:*:*:*:*range: <=1.30b06
- cpe:2.3:o:dlink:dir-882_firmware:1.30b06:hotfix_02_beta:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- supportannouncement.us.dlink.com/announcement/publication.aspxnvdVendor Advisory
- supportannouncement.us.dlink.com/announcement/publication.aspxnvdVendor Advisory
- www.dlink.com/en/security-bulletin/nvdVendor Advisory
- github.com/pjqwudi/my_vuln/blob/main/D-link/vuln_2/2.mdnvdBroken Link
News mentions
0No linked articles in our index yet.