No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 09 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 09 Apr 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
D-link
D-link dir-882 |
|
| Vendors & Products |
D-link
D-link dir-882 |
Thu, 09 Apr 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in D-Link DIR-882 1.01B02. Impacted is the function sprintf of the file prog.cgi of the component HNAP1 SetNetworkSettings Handler. The manipulation of the argument IPAddress results in os command injection. The attack may be performed from remote. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer. | |
| Title | D-Link DIR-882 HNAP1 SetNetworkSettings prog.cgi sprintf os command injection | |
| Weaknesses | CWE-77 CWE-78 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-09T12:41:29.493Z
Reserved: 2026-04-08T18:25:11.487Z
Link: CVE-2026-5844
Updated: 2026-04-09T12:41:25.511Z
Status : Received
Published: 2026-04-09T05:16:06.653
Modified: 2026-04-09T05:16:06.653
Link: CVE-2026-5844
No data.
OpenCVE Enrichment
Updated: 2026-04-09T08:24:57Z