important · Firmware — D-Link
Internet exploitation attempts now target an unpatched command-injection path on end-of-life D-Link DIR-882 routers.
Affects
D-Link DIR-882 wireless routers running end-of-life embedded firmware.
An anonymous request stores shell syntax in an NVRAM field that the router later concatenates into a twsystem command.
Detail and 3 sources
The evidence is ten honeypot connections recorded as attempts; it does not establish successful compromise or execution as root.
The product is end of life and will receive no fix.
Chain to watch
Reach an Internet-exposed DIR-882 management service→↓Store shell syntax through SetSysLogSettings→↓Observe whether the later command executes successfully and as which user→↓Successful compromise and root execution are not established by the available telemetry.
Unverified chainObtain a successful capture or reproduce a benign identity command on stock hardware.