CVE-2022-43633 is a critical arbitrary code execution vulnerability affecting D-Link DIR-1935 1.03 routers. The flaw resides in the web management portal's handling of SetSysLogSettings requests, specifically the IPAddress element, which improperly validates user-supplied input before executing a system call. This allows network-adjacent attackers to execute code as root, even though authentication is typically required, due to a bypassable authentication mechanism. The vulnerability carries a CVSS score of 6.8 (Medium), indicating a network-adjacent attack vector with low attack complexity, but high impact on confidentiality, integrity, and availability. Despite the authentication requirement, its bypass significantly lowers the practical hurdle for exploitation. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also minimal, suggesting a low level of public awareness or attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.02CPE matchmatch criteria | cpe:2.3:o:dlink:dir-1935_firmware:*:*:*:*:*:*:*:* | ||
1.03CPE matchmatch criteria | cpe:2.3:o:dlink:dir-1935_firmware:1.03:b1:*:*:*:*:*:* | ||
1.03CPE matchmatch criteria | cpe:2.3:o:dlink:dir-1935_firmware:1.03:b2:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.