CVE-2022-1262 is a command injection vulnerability (CWE-78) in the protest binary, affecting D-Link products. An authenticated attacker with remote command line interface access can execute arbitrary commands as root, leading to high confidentiality, integrity, and availability impacts. While rated as HIGH severity (CVSS 7.8), there is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.02b03CPE matchmatch criteria | cpe:2.3:o:dlink:dir-1360_firmware:1.02b03:*:*:*:*:*:*:* | ||
1.03b02CPE matchmatch criteria | cpe:2.3:o:dlink:dir-1360_firmware:1.03b02:*:*:*:*:*:*:* | ||
1.11b04CPE matchmatch criteria | cpe:2.3:o:dlink:dir-1360_firmware:1.11b04:*:*:*:*:*:*:* | ||
1.01b04CPE matchmatch criteria | cpe:2.3:o:dlink:dir-1760_firmware:1.01b04:*:*:*:*:*:*:* | ||
1.11b03CPE matchmatch criteria | cpe:2.3:o:dlink:dir-1760_firmware:1.11b03:beta:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Command Injection Vulnerability in /bin/protest Binary on Multiple D-Link Routers
Apr 6, 2022Command Injection Vulnerability in /bin/protest Binary on Multiple D-Link Routers
Apr 6, 2022Command Injection Vulnerability in /bin/protest Binary on Multiple D-Link Routers
Apr 6, 2022