CVE-2022-44928
CRITICALD-Link DVG-G5402SP GE_1.03 - OS Command Injection via Maintenance Function
Title source: llmDescription
D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.
References (1)
Core 1
Core References
Exploit, Third Party Advisory
https://cyber-guy.gitbook.io/cyber-guys-blog/pocs/cve-2022-44928
Scores
CVSS v3
9.8
EPSS
0.0271
EPSS Percentile
84.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (1)
d-link/dvg-g5402sp_firmware
ge_1.03
Published
Dec 02, 2022
Tracked Since
Feb 18, 2026