CVE-2022-28896: D-Link Dir-882 Firmware

Critical severity, CVSS 9.8. EPSS: 3.5% chance of exploitation in the next 30 days.

A command injection vulnerability in the component /setnetworksettings/SubnetMask of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload.

Affected products

  • D-Link Dir-882 Firmware: version 1.30b06 only

Published 2022-05-10. Last modified 2026-06-17.