Vulnerability Details CVE-2021-45998
D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the LocalIPAddress parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.037
EPSS Ranking 88.4%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2021-45998
-
cpe:2.3:h:dlink:dir-882:-
-
cpe:2.3:o:dlink:dir-882_firmware:-
-
cpe:2.3:o:dlink:dir-882_firmware:1.01b02
-
cpe:2.3:o:dlink:dir-882_firmware:1.10b02
-
cpe:2.3:o:dlink:dir-882_firmware:1.10b04
-
cpe:2.3:o:dlink:dir-882_firmware:1.20b06
-
cpe:2.3:o:dlink:dir-882_firmware:1.30
-
cpe:2.3:o:dlink:dir-882_firmware:1.30b06