CVE-2026-4499
7.3D-Link · DIR-820LW
A remote OS command injection vulnerability exists in the D-Link DIR-820LW 2.03 firmware due to improper input validation in the ssdpcgi_main function of the SSDP component.
Executive summary
An unauthenticated remote OS command injection vulnerability in D-Link DIR-820LW firmware version 2.03 poses a critical risk of full system compromise.
Vulnerability
The vulnerability is an OS command injection flaw (CWE-78) triggered via the HTTP_ST environment variable within the ssdpcgi_main function of the SSDP component. An unauthenticated remote attacker can exploit this by sending specially crafted packets to the affected device.
Business impact
Successful exploitation allows an unauthenticated attacker to execute arbitrary operating system commands with elevated privileges on the router. This can lead to complete device takeover, interception of network traffic, persistence within the local network, and potential pivot points for further attacks against internal systems. Given the CVSS score of 7.3, this represents a significant risk to network integrity and confidentiality.
Remediation
Immediate Action: Disconnect the affected device from the internet immediately and check the official D-Link support portal for firmware updates or security patches. If no patch is available, replace the device as it is currently vulnerable to remote exploitation.
Proactive Monitoring: Review firewall and router logs for anomalous traffic patterns, specifically looking for unusual HTTP requests or unexpected inbound SSDP traffic. Monitor for signs of unauthorized configuration changes or unexpected process execution on the device if management interfaces are accessible.
Compensating Controls: Disable UPnP and SSDP services on the router if they are not strictly required for network functionality to reduce the attack surface. Utilize a perimeter firewall to block inbound access to the router management and discovery ports from untrusted networks.
Exploitation status
Public Exploit Available: Yes, a proof of concept and technical details are available via the research documentation referenced in the CVE record.
Analyst recommendation
The presence of a public proof of concept combined with the ease of remote exploitation makes this a high priority for remediation. Administrators should prioritize the decommissioning or patching of these legacy devices, as they are likely to remain targets for automated exploitation attempts. If patching is not feasible, the device must be isolated from the public internet to prevent unauthorized remote command execution.
More D-Link CVEs
Sources
Originally found and disclosed by junqi (VulDB User), per the CVE Program record.
- VDB-352055 | D-Link DIR-820LW SSDP ssdpcgi_main os command injection Vulnerability database entry
- VDB-352055 | CTI Indicators (IOB, IOC, TTP, IOA)
- Submit #773883 | D-Link DIR-820LW B2.03 OS Command Injection Third-party advisory
- Issue tracker
- Exploit / PoC
- dlink.com