Skip to finding
important · Firmware — D-Link

Internet exploitation attempts now target an unpatched command-injection path on end-of-life D-Link DIR-882 routers.

Affects

D-Link DIR-882 wireless routers running end-of-life embedded firmware.

An anonymous request stores shell syntax in an NVRAM field that the router later concatenates into a twsystem command.

Detail and 3 sources

The evidence is ten honeypot connections recorded as attempts; it does not establish successful compromise or execution as root.

The product is end of life and will receive no fix.

Chain to watch
Reach an Internet-exposed DIR-882 management service→↓Store shell syntax through SetSysLogSettings→↓Observe whether the later command executes successfully and as which user→↓Successful compromise and root execution are not established by the available telemetry.
Unverified chainObtain a successful capture or reproduce a benign identity command on stock hardware.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, September 7, 2026