VYPR
Unrated severityNVD Advisory· Published May 18, 2022· Updated Aug 3, 2024

CVE-2022-28956

CVE-2022-28956

Description

An issue in the getcfg.php component of D-Link DIR816L_FW206b01 allows attackers to access the device via a crafted payload.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

D-Link DIR816L FW206b01's getcfg.php lacks authentication; sending a newline then AUTHORIZED_GROUP=1 bypasses access controls.

Vulnerability

The getcfg.php component in D-Link DIR816L firmware version DIR816L_FW206b01.bin fails to perform proper authentication checks. By sending a crafted payload containing a newline followed by AUTHORIZED_GROUP=1 (%0aAUTHORIZED_GROUP=1), an attacker can bypass the authentication mechanism. This issue exists in the getcfg.php endpoint of the firmware version DIR816L_FW206b01.bin [1].

Exploitation

An attacker needs network access to the affected device. No prior authentication is required. The exploit is performed by appending the string %0aAUTHORIZED_GROUP=1 to the request, which causes the device to treat the request as authorized. The proof-of-concept shows that without this payload, the device returns a "Not authorized" response; with the payload, access is granted [1].

Impact

Successful exploitation allows an unauthenticated attacker to bypass authentication and access the getcfg.php component, which may expose sensitive configuration data or enable further device compromise. The attacker gains unauthorized access to the device's web interface without valid credentials [1].

Mitigation

As of the publication date (2022-05-18), no official fix or patch has been publicly released by D-Link. The vendor's security bulletin page [2] does not list a specific advisory for this vulnerability at the time of writing. Users should consider isolating affected devices from untrusted networks and monitoring for future firmware updates. The device may also be approaching end-of-life (EOL) status.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • D-Link/DIR816Ldescription
  • Dlink/DIR816Lllm-create
    Range: FW206b01

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.