VYPR
Unrated severityNVD Advisory· Published May 10, 2022· Updated Aug 3, 2024

CVE-2022-28896

CVE-2022-28896

Description

A command injection vulnerability in the component /setnetworksettings/SubnetMask of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

D-Link DIR-882 DIR882A1_FW130B06 configuration endpoint /setnetworksettings/SubnetMask allows command injection, enabling privilege escalation to root.

Vulnerability

A command injection vulnerability exists in the /setnetworksettings/SubnetMask endpoint of the D-Link DIR-882 router running firmware version DIR882A1_FW130B06. The component fails to properly sanitize user-supplied input when setting the subnet mask, allowing an attacker to inject arbitrary operating system commands. The vulnerability is reachable through the web-based management interface.

Exploitation

An attacker with network access to the router's management interface can craft a malicious HTTP request to the /setnetworksettings/SubnetMask endpoint by including shell metacharacters in the SubnetMask parameter. The attacker does not require prior authentication if the management interface is exposed. The injected commands are executed with root privileges.

Impact

Successful exploitation allows the attacker to execute arbitrary commands on the underlying operating system with root-level privileges. This results in a complete compromise of the device's confidentiality, integrity, and availability.

Mitigation

D-Link has not released a firmware update addressing this vulnerability as of the publication date [1]. Users should restrict access to the management interface to trusted networks and disable remote administration if not required. The DIR-882 may be approaching end-of-life status; consult D-Link's support page for the latest information [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • D-Link/DIR882description
  • Dlink/DIR882llm-fuzzy
    Range: = A1_FW130B06

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.