cbcvebase.
CVE-2022-42156
published 2022-10-13

CVE-2022-42156: D-Link COVR 1200,1203 v1.08 was discovered to contain a command injection vulnerability via the tomography_ping_number parameter at function…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
D-Link COVR 1200,1203 v1.08 was discovered to contain a command injection vulnerability via the tomography_ping_number parameter at function SetNetworkTomographySettings.

Affected

4 ranges
VendorProductVersion rangeFixed in
dlinkcovr_1200_firmware
dlinkcovr_1202_firmware
dlinkcovr_1203_firmware
linuxlinux_kernel>= 0 < 5.4.0-202.2225.4.0-202.222

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv5.5MEDIUM