CVE-2024-33342: D-Link Dir-822+ Firmware

High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.

D-Link DIR-822+ V1.0.5 was found to contain a command injection in SetPlcNetworkpwd function of prog.cgi, which allows remote attackers to execute arbitrary commands via shell.

Affected products

  • D-Link Dir-822+ Firmware: version 1.05 only

Published 2024-04-26. Last modified 2026-06-17.