VYPR
Unrated severityNVD Advisory· Published May 10, 2022· Updated Aug 3, 2024

CVE-2022-28901

CVE-2022-28901

Description

A command injection vulnerability in the component /SetTriggerLEDBlink/Blink of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Command injection in D-Link DIR882's LED blink function allows unauthenticated attackers to escalate privileges to root.

Vulnerability

A command injection vulnerability exists in the /SetTriggerLEDBlink/Blink component of D-Link DIR882 routers running firmware version DIR882A1_FW130B06. The affected endpoint fails to properly sanitize user-supplied input before incorporating it into a system command, allowing an attacker to inject arbitrary commands. No authentication is required to reach this endpoint.

Exploitation

An attacker with network access to the device can send a crafted HTTP request to the /SetTriggerLEDBlink/Blink endpoint with a malicious payload in the parameter that triggers the command injection. The attacker does not need any prior authentication or user interaction. The injected commands execute in the context of the web server, which typically runs with root privileges on this model [1].

Impact

Successful exploitation allows the attacker to execute arbitrary operating system commands with root privileges, leading to full compromise of the device. The attacker can read, modify, or delete sensitive data, install malware, or use the device as a pivot for further attacks on the network.

Mitigation

As of the publication date (2022-05-10), D-Link has not released a firmware update to address this vulnerability. Users should monitor D-Link's security bulletin page [1] for any future patches. If the device is no longer supported (end-of-life), consider replacing it with a model that receives security updates. As a workaround, restrict network access to the device's management interface to trusted hosts only.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • D-Link/DIR882description
  • Dlink/DIR882llm-fuzzy
    Range: = DIR882A1_FW130B06

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.