CVE-2026-4499 Details
Description
A vulnerability was determined in D-Link DIR-820LW 2.03. Affected is the function ssdpcgi_main of the component SSDP. Executing a manipulation can lead to os command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
A critical OS command injection vulnerability has been identified in the D-Link DIR-820LW router running version 2.03. The issue arises in the 'ssdpcgi_main' function, which processes SSDP (Simple Service Discovery Protocol) M-SEARCH requests. The vulnerability allows remote, unauthenticated attackers to execute arbitrary system commands with root privileges by sending specially crafted SSDP packets. This exploitation takes advantage of the function's failure to properly sanitize or escape input from the HTTP_ST (Search Target) environment variable before incorporating it into a shell command.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/user-attachments/files/25790888/OS.Command.Injection.in.D-Link.DIR-820LW.B2.03.via.the.HTTP_ST.environment.variable.in.ssdpcgi_main.function.zip | [email protected] | Exploit |
| https://github.com/yunleeeee/cve/issues/1 | [email protected] | Exploit |
| https://vuldb.com/?ctiid.352055 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.352055 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.773883 | [email protected] | Third Party AdvisoryVDB Entry |
| https://www.dlink.com/ | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dlink dir-820lw firmware | 2.03 |
CPE
Remediation
| |
| dlink dir-820lw | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Apr 3, 2026 | Initial Analysis | [email protected] |
| Mar 20, 2026 | New CVE Received | [email protected] |