{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/dsl-3782-2016-07-28/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:h:dlink:dsl-3782:2016-07-28:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-90880"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DSL-3782 (2016-07-28)"],"_cs_severities":["high"],"_cs_tags":["cve-2026-90880","command-injection","network-security"],"_cs_type":"advisory","_cs_vendors":["D-Link"],"content_html":"\u003cp\u003eA command injection vulnerability (CVE-2026-90880) has been identified in the D-Link DSL-3782 router, specifically within the 2016-07-28 firmware version. The flaw resides in the Diagnostics component, triggered by improper input validation within the system function handling the /cgi-bin/New_GUI/Set/Diagnostics.asp script. An unauthenticated remote attacker can inject malicious shell commands by manipulating the Addr argument. Publicly available exploit code exists, increasing the risk of exploitation for remote system compromise or unauthorized access to the network device. Defenders should prioritize isolating vulnerable legacy hardware, as these devices are often targeted for inclusion in botnets or used as entry points into internal networks.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify reachable D-Link DSL-3782 management interfaces.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP GET or POST request targeting the /cgi-bin/New_GUI/Set/Diagnostics.asp endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker injects shell metacharacters or command strings into the 'Addr' parameter (e.g., ; id or | /bin/sh).\u003c/li\u003e\n\u003cli\u003eThe router's web server processes the request and passes the tainted 'Addr' value to a system-level function without proper sanitization.\u003c/li\u003e\n\u003cli\u003eThe underlying operating system executes the attacker-supplied command with root or administrative privileges.\u003c/li\u003e\n\u003cli\u003eThe attacker establishes a reverse shell or downloads a malicious payload to gain persistent access to the device.\u003c/li\u003e\n\u003cli\u003eFinal objective: The device is recruited into a botnet or used as a pivot point for lateral movement into the local network.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full system control over the affected D-Link DSL-3782 router. This can lead to unauthorized network monitoring, traffic interception, internal network reconnaissance, and the deployment of malware. As this device is a consumer-grade router, impact includes potential data exfiltration and complete loss of confidentiality and integrity for all traffic traversing the device.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor network traffic for anomalous HTTP requests directed at /cgi-bin/New_GUI/Set/Diagnostics.asp containing shell metacharacters.\u003c/li\u003e\n\u003cli\u003eDisconnect affected D-Link DSL-3782 devices from the public internet immediately.\u003c/li\u003e\n\u003cli\u003eIf a firmware update is unavailable, ensure the web management interface is not accessible from the WAN side.\u003c/li\u003e\n\u003cli\u003eImplement egress filtering on the gateway to detect and block non-standard outbound connections originating from network infrastructure components.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T05:38:59Z","date_published":"2026-09-15T05:38:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-dlink-command-injection/","summary":"An unauthenticated remote command injection vulnerability in the D-Link DSL-3782 router allows attackers to execute arbitrary system commands via the Diagnostics component.","title":"Remote Command Injection in D-Link DSL-3782","url":"https://feed.craftedsignal.io/briefs/2026-09-dlink-command-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - DSL-3782 (2016-07-28)","version":"https://jsonfeed.org/version/1.1"}