← Back to browse · API

CVE-2024-33344

Severity
CRITICAL
CVSS
9.8
EPSS
0.19893
Risk score
46.16
CISA KEV
No
PoC
No
Published
2024-04-26
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2024-31086, GHSA-6VQG-9P93-6R8W
Products
n/a:n/a n/a
Sources
euvd EUVD-2024-31086

Description

D-Link DIR-822+ V1.0.5 was found to contain a command injection in ftext function of upload_firmware.cgi, which allows remote attackers to execute arbitrary commands via shell.

References