← Back to browse · API

CVE-2022-44808

Severity
CRITICAL
CVSS
9.8
EPSS
0.03826
Risk score
40.54
CISA KEV
No
PoC
No
Published
2022-11-22
Modified
2025-04-25
First seen
2026-08-07
Aliases
EUVD-2022-47739, GHSA-QVJ8-QCRX-49C6
Products
n/a:n/a n/a
Sources
euvd EUVD-2022-47739

Description

A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary operating system commands through well-designed /HNAP1 requests. Before the HNAP API function can process the request, the system function executes an untrusted command that triggers the vulnerability.

References