Vulnerability Description
A command injection vulnerability in the protest binary allows an attacker with access to the remote command line interface to execute arbitrary commands as root.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dir-1360 Firmware | 1.02b03 |
| Dlink | Dir-1360 | a1 |
| Dlink | Dir-1760 Firmware | 1.01b04 |
| Dlink | Dir-1760 | - |
| Dlink | Dir-1960 Firmware | 1.02b01 |
| Dlink | Dir-1960 | a1 |
| Dlink | Dir-2640 Firmware | 1.11b02 |
| Dlink | Dir-2640 | - |
| Dlink | Dir-2660 Firmware | 1.04b03 |
| Dlink | Dir-2660 | a1 |
| Dlink | Dir-3040 Firmware | 1.13b03 |
| Dlink | Dir-3040 | - |
| Dlink | Dir-3060 Firmware | 1.00b12 |
| Dlink | Dir-3060 | - |
| Dlink | Dir-867 Firmware | 1.20b10 |
| Dlink | Dir-867 | a1 |
| Dlink | Dir-878 Firmware | 1.20b05 |
| Dlink | Dir-878 | - |
| Dlink | Dir-882 Firmware | 1.20b06 |
| Dlink | Dir-882 | - |
Related Weaknesses (CWE)
References
- https://www.tenable.com/security/research/tra-2022-09ExploitThird Party Advisory
- https://www.tenable.com/security/research/tra-2022-09ExploitThird Party Advisory
FAQ
What is CVE-2022-1262?
CVE-2022-1262 is a vulnerability with a CVSS score of 7.8 (HIGH). A command injection vulnerability in the protest binary allows an attacker with access to the remote command line interface to execute arbitrary commands as root.
How severe is CVE-2022-1262?
CVE-2022-1262 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-1262?
Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dir-1360 Firmware, Dlink Dir-1360, Dlink Dir-1760 Firmware, Dlink Dir-1760, Dlink Dir-1960 Firmware.