CVE-2022-48108: D-Link Dir 878 Firmware

Critical severity, CVSS 9.8. EPSS: 3.1% chance of exploitation in the next 30 days.

D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /SetNetworkSettings/SubnetMask. This vulnerability allows attackers to escalate privileges to root via a crafted payload.

Affected products

  • D-Link Dir 878 Firmware: version 1.30b08 only

Published 2023-01-27. Last modified 2026-06-17.