Critical severity9.8NVD Advisory· Published Nov 22, 2022· Updated Jun 17, 2026
CVE-2022-44808
CVE-2022-44808
Description
A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary operating system commands through well-designed /HNAP1 requests. Before the HNAP API function can process the request, the system function executes an untrusted command that triggers the vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:o:dlink:dir-823g_firmware:1.02b03:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- github.com/RobinWang825/IoT_vuln/tree/main/D-Link/DIR-823G/2nvdExploitThird Party Advisory
- www.dlink.com/en/security-bulletin/nvdVendor Advisory
- github.com/726232111/VulIoT/tree/main/D-Link/DIR823G%20V1.0.2B05/HNAP1nvd
News mentions
0No linked articles in our index yet.