OpsBuzz

Alert

D-Link DIR-820 Router OS Command Injection Vulnerability

D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a cr

Security · HIGH
Source: CISA Known Exploited VulnerabilitiesMay 2, 2026, 4:51 PMSecurityhigh

Full content

D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.

Vendor: D-Link

Product: DIR-820 Router

Due date: 2024-10-21

Known ransomware use: Unknown

Why it matters

The impacted product is end-of-life EoL and/or end-of-service EoS . Users should discontinue utilization of the product.

Related alerts