CVE-2026-5844Disclosure(dlink / dir-882)

LOWCVSS 7.3 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for dlink dir-882 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was found in D-Link DIR-882 1.01B02. Impacted is the function sprintf of the file prog.cgi of the component HNAP1 SetNetworkSettings Handler. The manipulation of the argument IPAddress results in os command injection. The attack may be performed from remote. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.

3.5/ 10 priority

Sources & remediation

Exploit / PoC references
Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dir-882
  • dir-882_firmware

Threat summary

  • Public PoC and exploit tooling are both present
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-09); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
dir-882dir-882_firmware

2 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-09: 2Mentions · 2026-04-10: 1PoC Mentioned / Linked · 2026-04-09: 1Exploit Tool / Code · 2026-04-09: 1Technical Details · 2026-04-09: 2Technical Details · 2026-04-10: 104-0904-10
Signal classification3 categories
Disclosure
133.3%
Exploit
133.3%
General
133.3%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-04-092
Disclosure1Exploit1
2026-04-101
General1
Full discourse3 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-5844 📊 Severity: 7.2 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5844 #CVE-2026-5844 #CVE #High #CyberSecurity #InfoSec https://t.co/M9PZHFLfKI

    Post summary

    The tweet announces CVE-2026-5844 with a 7.2 severity score and indicates a high risk, but it does not provide evidence of exploitation, a PoC, or a fix.

    0000030
    123 followersView on X
  • dbugs@ptdbugs
    Exploit

    D-Link DIR-882 HNAP1 SetNetworkSettings prog.cgi sprintf os command injection CVE: CVE-2026-5844 PT ID: PT-2026-31585 Vendor: D-link Product: DIR-882 CVSS: 8.6 Credits: meshaal (VulDB User) Description: A vulnerability was found in D-Link DIR-882 1.01B02. Impacted is the function sprintf of the file prog.cgi of the component HNAP1 SetNetworkSettings Handler. The manipulation of the argument IPAddress results in os command injection. The attack may be performed from remote. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-5844 • https://vuldb.com/vuln/356329 • https://vuldb.com/vuln/356329/cti • https://vuldb.com/submit/790290 • https://files.catbox.moe/ei31k1.zip • https://www.dlink.com/ #dbugs_vuln

    Post summary

    The D‑Link DIR‑882 vulnerability (CVE‑2026‑5844) allows remote OS command injection via a publicly available exploit, but no patch or active exploitation is reported.

    00000100
    788 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5844 Remote OS Command Injection in D-Link DIR-882 1.01B02 HNAP1 SetNetworkSet... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5844 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The text announces a remote OS command injection CVE (CVE‑2026‑5844) for a D‑Link router, linking to a vulnerability notification, but offers no exploitation, patch, or PoC details.

    0000052
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdir-882a1--
OSdlinkdir-882_firmware1.01b02--

Explore more