Vulnerability Description
D-Link COVR 1200,1202,1203 v1.08 was discovered to contain a command injection vulnerability via the system_time_timezone parameter at function SetNTPServerSettings.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Covr 1203 Firmware | 1.08 |
| Dlink | Covr 1203 | - |
| Dlink | Covr 1202 Firmware | 1.08 |
| Dlink | Covr 1202 | - |
| Dlink | Covr 1200 Firmware | 1.08 |
| Dlink | Covr 1200 | - |
Related Weaknesses (CWE)
References
- https://github.com/14isnot40/vul_discovery/blob/master/D-Link%20COVR%2012xx%20.pExploitThird Party Advisory
- https://www.dlink.com/en/security-bulletin/Vendor Advisory
- https://github.com/14isnot40/vul_discovery/blob/master/D-Link%20COVR%2012xx%20.pExploitThird Party Advisory
- https://www.dlink.com/en/security-bulletin/Vendor Advisory
FAQ
What is CVE-2022-42160?
CVE-2022-42160 is a vulnerability with a CVSS score of 8.8 (HIGH). D-Link COVR 1200,1202,1203 v1.08 was discovered to contain a command injection vulnerability via the system_time_timezone parameter at function SetNTPServerSettings.
How severe is CVE-2022-42160?
CVE-2022-42160 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-42160?
Check the references section above for vendor advisories and patch information. Affected products include: Dlink Covr 1203 Firmware, Dlink Covr 1203, Dlink Covr 1202 Firmware, Dlink Covr 1202, Dlink Covr 1200 Firmware.