TyeYeah/DIR-890L-1.20-RCE

TyeYeah/DIR-890L-1.20-RCE

Releases0
Stars1
Analysis and PoC for D-Link DIR-890L RCE (CVE-2022-29778)

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH6.5 MEDIUM

D-Link DIR-890L 1.20b01 allows attackers to execute arbitrary code due to the hardcoded option Wake-On-Lan for the parameter 'descriptor' at SetVirtualServerSettings.php