CVE-2024-22651
Description
There is a command injection vulnerability in the ssdpcgi_main function of cgibin binary in D-Link DIR-815 router firmware v1.04.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A command injection vulnerability in the ssdpcgi_main function of the DIR-815 router firmware ≤v1.04 allows attackers to execute arbitrary commands via unvalidated input.
Vulnerability
The vulnerability is a command injection in the ssdpcgi_main function of the cgibin binary in D-Link DIR-815 router firmware version 1.04 and earlier. The function obtains user-supplied data from the web interface via getenv and passes it directly to lxmldbc_system, a system wrapper, without any sanitization. This allows an attacker to inject arbitrary commands into the system call. [1]
Exploitation
An attacker with network access to the router's web interface can send a crafted request containing malicious command payloads. No authentication is required if the web interface is exposed. The attacker can reproduce the vulnerability by emulating the firmware using FirmAE and then executing the provided proof-of-concept code. [1]
Impact
Successful exploitation grants the attacker shell privileges on the device, enabling full compromise of the router. This includes the ability to intercept network traffic, modify configuration, compromise connected hosts, or launch further attacks. [1]
Mitigation
As of the publication date (2024-01-24), no official patch has been released. Users should restrict access to the router's web interface to trusted networks only. The affected firmware version v1.04 may be the final release for this device, suggesting that the product might be end-of-life; upgrading to a different router model is recommended. [1]
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.