CVE-2022-44929
CRITICALD-Link DVG-G5402SP GE_1.03 - Unauthenticated Privilege Escalation via VoIP SIB Profile Editing
Title source: llmDescription
An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP SIB profiles.
References (1)
Core 1
Core References
Exploit, Third Party Advisory
https://cyber-guy.gitbook.io/cyber-guys-blog/pocs/cve-2022-44929
Scores
CVSS v3
9.8
EPSS
0.0112
EPSS Percentile
61.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-276
Status
published
Products (1)
d-link/dvg-g5402sp_firmware
ge_1.03
Published
Dec 02, 2022
Tracked Since
Feb 18, 2026